Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18857

Опубликовано: 20 нояб. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "command_line" parameter as a shell command.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:liquidvpn:liquidvpn:*:*:*:*:*:macos:*:*
Версия до 1.37 (включая)

EPSS

Процентиль: 65%
0.00496
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "command_line" parameter as a shell command.

EPSS

Процентиль: 65%
0.00496
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-78