Impact
An unprivileged user running Pi‑hole can replace the /etc/pihole/logrotate file. The pihole‑FTL‑prestart.sh script then changes the file ownership to root:root, and the daily pihole flush cron, running as root, parses the file and executes the specified firstaction shell with uid 0. This chain of events allows the attacker to run arbitrary commands as root, effectively escalating local privileges.
Affected Systems
The vulnerability affects Pi‑hole versions from 6.0 through 6.4.2. The affected product is Pi‑hole by the pi‑hole vendor. Updating to Pi‑hole 6.4.3 or later eliminates the issue.
Risk and Exploitability
The CVSS score of 8.8 marks this flaw as high severity. The EPSS score of less than 1% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local code execution as the pihole user, so the vector is local. Once exploited, an attacker gains root privileges on the host.
OpenCVE Enrichment