# CVE-2013-10052

## Summary

- **CVE ID:** CVE-2013-10052
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-269
- **Published:** Aug 4, 2025
- **Last Modified:** Apr 7, 2026

## Description

ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be invoked by low-privileged users to execute arbitrary commands as root. This flaw enables local attackers with shell access to escalate privileges by writing a payload to a writable directory and executing it via zsudo. The vulnerability is particularly impactful in post-exploitation scenarios following web server compromise, where the attacker inherits access to zsudo.

## Affected Products

- ZPanel Project — ZPanel (*)

## References

- [CNA](https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/local/zpanel_zsudo.rb)
- [CNA](https://www.exploit-db.com/exploits/26451)
- [CNA](https://github.com/zpanel/zpanelx)
- [CNA](https://www.vulncheck.com/advisories/zpanel-zsudo-local-priv-esc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.58%
- **EPSS Percentile:** 81.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._