{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/below--0.9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:facebook:below:*:*:*:*:*:rust:*:*"],"_cs_cves":[{"cvss":6.8,"id":"CVE-2025-27591"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Below (\u003c 0.9.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Facebook"],"content_html":"\u003cp\u003eCVE-2025-27591 is a local privilege escalation vulnerability affecting the Facebook 'below' system monitoring tool, specifically versions prior to 0.9.0. The vulnerability originates from the insecure management of log files when the application is executed with elevated privileges, specifically using the 'below record' command. An attacker with local access to the system can leverage a symlink attack to redirect the application's error logging to critical system files, such as /etc/passwd. By exploiting this behavior, an attacker can append a malicious user entry to the password file, effectively granting them unauthorized root-level access. The proof-of-concept exploit is publicly available, increasing the risk for environments where 'below' is installed and used with sudo permissions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker ensures the application's target log file, typically located at /var/log/below/error_root.log, does not already exist.\u003c/li\u003e\n\u003cli\u003eThe attacker creates a symbolic link at /var/log/below/error_root.log that points to the system's /etc/passwd file.\u003c/li\u003e\n\u003cli\u003eThe attacker executes the 'below' binary with elevated privileges using the 'sudo /usr/bin/below record' command.\u003c/li\u003e\n\u003cli\u003eThe application, running as root, attempts to write error logs to the path redirected by the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker provides crafted input designed to trigger an error, causing the application to write data into the target /etc/passwd file.\u003c/li\u003e\n\u003cli\u003eThe attacker verifies that a new, unauthorized user has been successfully appended to the /etc/passwd configuration.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the newly created credentials to authenticate and obtain a root shell on the system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2025-27591 results in full system compromise. An unprivileged attacker can escalate to root privileges, gaining complete control over the affected host. This vulnerability impacts systems where 'below' is installed and invoked via sudo, common in development, testing, or infrastructure monitoring environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of the Facebook 'below' monitoring tool to version 0.9.0 or later to remediate the insecure log file handling. If patching cannot be performed immediately, monitor for unauthorized symbolic link creation within the /var/log/below/ directory.\u003c/p\u003e\n\u003ch2 id=\"tags\"\u003eTags\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eprivilege-escalation\u003c/li\u003e\n\u003cli\u003elinux\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T01:09:30Z","date_published":"2026-09-01T01:09:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-27591-below/","summary":"A local privilege escalation vulnerability in the 'below' system monitoring tool allows attackers to gain root access via a symlink attack targeting log files.","title":"Local Privilege Escalation in Facebook Below (CVE-2025-27591)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-27591-below/"}],"language":"en","title":"CraftedSignal Threat Feed - Below (\u003c 0.9.0)","version":"https://jsonfeed.org/version/1.1"}