Critical Privilege Escalation Vulnerability in LiteSpeed Web Server Enterprise Allows Root Access on Shared Hosting
A critical privilege escalation vulnerability in LiteSpeed Web Server Enterprise allows low-privilege hosting accounts to gain root access on shared servers, potentially compromising multiple websites and server configurations. Administrators are urged to update to version 6.3.7 immediately, as the flaw remains unpatched in older versions and no public exploit details have been disclosed.
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14.
On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,
*** END OF TRANSMISSION ***