CVE-2013-10052 - CVE House
Back to Database
Status published High CVE-2013-10052

ZPanel zsudo Local Privilege Escalation

Vulnerability Description

ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be invoked by low-privileged users to execute arbitrary commands as root. This flaw enables local attackers with shell access to escalate privileges by writing a payload to a writable directory and executing it via zsudo. The vulnerability is particularly impactful in post-exploitation scenarios following web server compromise, where the attacker inherits access to zsudo.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10052

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • sinn3r
  • juan vazquez

Affected Vendor

ZPanel Project

View all reports →

Affected Software

ZPanel
Vulnerable Versions:
*

Timeline

Official Publish: August 4th, 2025
Last Modified: April 7th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)