PT-2025-20735 · Cscreen+1 · Screen+1

Matthias Gerstner

·

Published

2025-05-12

·

Updated

2025-09-10

·

CVE-2025-46803

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Screen (affected versions not specified)
Description The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, allowing anyone to write to any Screen PTYs in the system. This change in mode allows for escalation of privilege.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2025-11402
CVE-2025-46803

Affected Products

Red Os
Screen