CVE-2025-66004
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-66004 is a path traversal vulnerability in usbmuxd (the USB multiplexer daemon used to communicate with iOS devices) that allows local users to escalate privileges to the service user account. The vulnerability is classified under CWE-35 (Path Traversal: '.../...//') and affects all versions of usbmuxd prior to commit 3ded00c9985a5108cfc7591a309f9a23d57a8cba. It was published on December 10, 2025, with the assigner listed as SUSE. The CVSS v3.1 base score is 5.7 (Medium), and the CVSS v4.0 base score is 5.1 (Medium) (ENISA EUVD, SUSE Bugzilla).

Technical details

The root cause is improper limitation of a pathname to a restricted directory (CWE-35 / CWE-22), where usbmuxd fails to adequately sanitize path components in user-controlled input, enabling directory traversal sequences such as .../...// to escape intended boundaries. A local attacker without any special privileges or user interaction can exploit this flaw to write or manipulate files accessible to the usbmuxd service user, effectively achieving a local privilege escalation. The fix is available in the upstream commit 3ded00c9985a5108cfc7591a309f9a23d57a8cba in the libimobiledevice/usbmuxd repository (ENISA EUVD, SUSE Bugzilla).

Impact

Successful exploitation allows a local unprivileged user to escalate to the usbmuxd service user, enabling unauthorized modification of files owned by that service account and potential disruption of the usbmuxd service (availability impact). While confidentiality impact is rated as none, the integrity and availability of the service and its associated files are at risk. In environments where the usbmuxd service user has elevated permissions or access to sensitive resources, this could serve as a stepping stone for further privilege escalation (ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the available data, though a reference to a Sploitus/PacketStorm entry (PACKETSTORM:216862) suggests exploit material may have been published. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (multiple plugin IDs: 278164, 279050, 279497, 281803, 281908, 307629) and Qualys (360245, 361584, 760323) (Feedly, Sploitus).

Exploitation steps

  1. Local Access: Obtain a local shell on a system running a vulnerable version of usbmuxd (prior to commit 3ded00c9985a5108cfc7591a309f9a23d57a8cba) as any unprivileged user.
  2. Identify usbmuxd service: Confirm usbmuxd is running and identify the service user account it operates under (commonly usbmux or similar).
  3. Craft traversal path: Construct a path using traversal sequences (e.g., .../...//) that usbmuxd processes without proper sanitization, targeting files writable by the service user.
  4. Trigger path traversal: Interact with the usbmuxd socket or relevant interface to supply the crafted path, causing usbmuxd to read from or write to an unintended location outside its restricted directory.
  5. Achieve privilege escalation: Leverage the ability to write files as the service user to escalate privileges — for example, by overwriting configuration files, cron jobs, or other artifacts accessible to the service account.

Indicators of compromise

  • Logs: Unexpected file access or write operations in directories outside usbmuxd's expected working paths in system logs (e.g., /var/log/syslog, /var/log/messages); usbmuxd error messages referencing unusual or malformed path strings.
  • File System: Newly created or modified files in directories owned by the usbmuxd service user that are outside the expected /var/lib/usbmuxd or similar service directories; presence of .../ or ..// patterns in usbmuxd-related log entries.
  • Process: Unexpected processes spawned under the usbmuxd service user account; unusual child processes of usbmuxd (e.g., shells or scripting interpreters).
  • Network: Anomalous connections from the usbmuxd service user to internal systems, which may indicate lateral movement following privilege escalation.

Mitigation and workarounds

The primary remediation is to update usbmuxd to a version that includes upstream commit 3ded00c9985a5108cfc7591a309f9a23d57a8cba or later. Distribution-specific patches have been released for Ubuntu (USN-7929-1), Debian (DSA-6125-1, DLA-4417-1), Amazon Linux 2 (ALAS2-2025-3111), SUSE, and Mageia. Administrators should apply the relevant vendor security update as soon as possible. As a temporary workaround, restricting local user access to the usbmuxd socket can reduce exposure until patching is feasible (Ubuntu Advisory, Debian Advisory, Amazon Linux).

Community reactions

The vulnerability received coverage across Linux security news outlets and distribution security announcement lists, including Ubuntu, Debian, Amazon Linux 2, SUSE, and Mageia advisories. Pro-Linux.de published multiple security notices covering the file overwrite risk in usbmuxd. Community discussion was limited, reflecting the moderate severity and local-only attack vector of the vulnerability (Pro-Linux, LinuxCompatible).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management