
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66004 is a path traversal vulnerability in usbmuxd (the USB multiplexer daemon used to communicate with iOS devices) that allows local users to escalate privileges to the service user account. The vulnerability is classified under CWE-35 (Path Traversal: '.../...//') and affects all versions of usbmuxd prior to commit 3ded00c9985a5108cfc7591a309f9a23d57a8cba. It was published on December 10, 2025, with the assigner listed as SUSE. The CVSS v3.1 base score is 5.7 (Medium), and the CVSS v4.0 base score is 5.1 (Medium) (ENISA EUVD, SUSE Bugzilla).
The root cause is improper limitation of a pathname to a restricted directory (CWE-35 / CWE-22), where usbmuxd fails to adequately sanitize path components in user-controlled input, enabling directory traversal sequences such as .../...// to escape intended boundaries. A local attacker without any special privileges or user interaction can exploit this flaw to write or manipulate files accessible to the usbmuxd service user, effectively achieving a local privilege escalation. The fix is available in the upstream commit 3ded00c9985a5108cfc7591a309f9a23d57a8cba in the libimobiledevice/usbmuxd repository (ENISA EUVD, SUSE Bugzilla).
Successful exploitation allows a local unprivileged user to escalate to the usbmuxd service user, enabling unauthorized modification of files owned by that service account and potential disruption of the usbmuxd service (availability impact). While confidentiality impact is rated as none, the integrity and availability of the service and its associated files are at risk. In environments where the usbmuxd service user has elevated permissions or access to sensitive resources, this could serve as a stepping stone for further privilege escalation (ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available data, though a reference to a Sploitus/PacketStorm entry (PACKETSTORM:216862) suggests exploit material may have been published. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (multiple plugin IDs: 278164, 279050, 279497, 281803, 281908, 307629) and Qualys (360245, 361584, 760323) (Feedly, Sploitus).
3ded00c9985a5108cfc7591a309f9a23d57a8cba) as any unprivileged user.usbmux or similar)..../...//) that usbmuxd processes without proper sanitization, targeting files writable by the service user./var/log/syslog, /var/log/messages); usbmuxd error messages referencing unusual or malformed path strings./var/lib/usbmuxd or similar service directories; presence of .../ or ..// patterns in usbmuxd-related log entries.The primary remediation is to update usbmuxd to a version that includes upstream commit 3ded00c9985a5108cfc7591a309f9a23d57a8cba or later. Distribution-specific patches have been released for Ubuntu (USN-7929-1), Debian (DSA-6125-1, DLA-4417-1), Amazon Linux 2 (ALAS2-2025-3111), SUSE, and Mageia. Administrators should apply the relevant vendor security update as soon as possible. As a temporary workaround, restricting local user access to the usbmuxd socket can reduce exposure until patching is feasible (Ubuntu Advisory, Debian Advisory, Amazon Linux).
The vulnerability received coverage across Linux security news outlets and distribution security announcement lists, including Ubuntu, Debian, Amazon Linux 2, SUSE, and Mageia advisories. Pro-Linux.de published multiple security notices covering the file overwrite risk in usbmuxd. Community discussion was limited, reflecting the moderate severity and local-only attack vector of the vulnerability (Pro-Linux, LinuxCompatible).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."