Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-27591 PoC — below 安全漏洞

Source
Associated Vulnerability
Title: below 安全漏洞 (CVE-2025-27591)
Description:A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
Description
A Proof of Concept for CVE-2025-27591, a local privilege escalation in Below ≤ v0.8.1
Readme
# CVE-2025-27591 PoC: Local Privilege Escalation in Below < v0.9.0

Proof of Concept for CVE-2025-27591, a vulnerability that allows to local unprivileged users to escalate their privileges to root through symlink attacks.

# 🕵️‍♂️ Technical Details

The vulnerability affects the Below service (versions prior to v0.9.0). It creates a /var/log/below directory with world-writable permissions (0777), allowing unprivileged local users to relocate symbolic links and manipulate critical files such as /etc/shadow, resulting in escalation to root.

## 🧩 Impact

A local, unprivileged user can escalate to root by:
- Creating a symlink in /var/log/below to a sensitive system file.
- Triggering the service with sudo (e.g., sudo below snapshot), causing Below to write to the symlink with root privileges.

## ✅ Requirements

- `/var/log/below/` must have world-writable permissions (0777) and contain the error_root.log file.
- You must be allowed to use sudo /usr/bin/below.

~~~ bash
foo@victim:~$ ls -l /var/log/ | grep below
drwxrwxrwx  3 root      root               4096 Jul  8 20:45 below
~~~

# 🛠️ Usage

We will need privileges at the sudoers level.
~~~ bash
foo@victim:~$ sudo -l
Matching Defaults entries for jacob on victim:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User foo may run the following commands on victim:
    (ALL : ALL) NOPASSWD: /usr/bin/below
~~~

Once we have the `poc.sh` file, we will give it the necessary permissions, execute it, and we'll be `root`.

~~~ bash
foo@victim:/tmp$ chmod +x poc.sh
foo@victim:/tmp$ ./poc.sh 
evil@victim:/tmp# id
uid=0(evil) gid=0(root) groups=0(root)
~~~

## ✅ Official Fix

Upgrade to Below v0.9.0 or later, which removes the insecure chmod logic and relies on systemd unit features like `LogsDirectory=below`

## ⚖️ Legal

- This script is for educational purposes. Always obtain explicit permission before testing.

## 📚 References
- [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-27591)
- [wiz.io](https://www.wiz.io/vulnerability-database/cve/cve-2025-27591)
- [SUSE Security](https://security.opensuse.org/2025/03/12/below-world-writable-log-dir.html)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →