Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18859

Опубликовано: 20 нояб. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the value of the "tun_path" or "tap_path" pathname in a kextload() call.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:liquidvpn:liquidvpn:*:*:*:*:*:macos:*:*
Версия до 1.37 (включая)

EPSS

Процентиль: 65%
0.00496
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the value of the "tun_path" or "tap_path" pathname in a kextload() call.

EPSS

Процентиль: 65%
0.00496
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-78