CVE-2025-66431
7.8WebPros · Plesk
A symlink following vulnerability in WebPros Plesk allows authenticated users with specific domain management permissions to execute arbitrary code as root during the domain creation process.
Executive summary
A critical vulnerability in WebPros Plesk allows authenticated users to achieve root-level code execution by exploiting a symlink flaw during domain management operations.
Vulnerability
The flaw is rooted in an improper handling of UNIX symbolic links (CWE-61) during the domain creation process. Attackers possessing the "Create and manage sites" privilege with "Domains management" and "Subdomains management" can leverage this to gain root privileges on the underlying Linux host.
Business impact
Successful exploitation results in full system compromise, as the attacker gains root-level access to the server. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to unauthorized data access, complete server takeover, and potential lateral movement within the hosting environment.
Remediation
Immediate Action: Update Plesk to version 18.0.73.5 or 18.0.74.2 or higher immediately as specified in the official vendor release notes.
Proactive Monitoring: Review system logs for unusual domain creation activity or unexpected process execution occurring with root privileges.
Compensating Controls: Restrict administrative panel access to trusted IP addresses and audit user permissions to ensure only necessary personnel have the required "Domains management" capabilities.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability poses a substantial threat to the integrity and confidentiality of the entire hosting server. Administrators should prioritize patching immediately to eliminate the risk of privilege escalation. If patching is delayed, audit existing user accounts for excessive privileges to minimize the potential attack surface.