Unknown · Mcsmanager · CVE-2025-50691
Name of the Vulnerable Software and Affected Versions:
MCSManager version 10.5.3
Description:
The MCSManager daemon process runs with root privileges by default. Sensitive data, including tokens and terminal content, is stored in a data directory accessible to all users. This allows unauthorized users to read the daemon’s key and potentially log in, leading to privilege escalation.
Recommendations:
Ensure the MCSManager daemon process does not run with root privileges.
Restrict access to the data directory containing sensitive information to authorized users only.