CVE-2018-10192
Last modified
CVE-2018-10192 is a vulnerability of currently unknown severity. IPVanish 3.0.11 for macOS suffers from a root privilege escalation vulnerability. The `com.ipvanish.osx.vpnhelper` LaunchDaemon implements an insecure XPC service that could allow an attacker to execute arbitrary code as the root user. EPSS estimates a 2.41% chance of exploitation in the next 30 days.
Description
IPVanish 3.0.11 for macOS suffers from a root privilege escalation vulnerability. The `com.ipvanish.osx.vpnhelper` LaunchDaemon implements an insecure XPC service that could allow an attacker to execute arbitrary code as the root user. IPVanish uses a third-party library for converting `xpc_object_t` types in to `NSObject` types for sending XPC messages. When IPVanish establishes a new connection, the following XPC message is sent to the `com.ipvanish.osx.vpnhelper` LaunchDaemon. Because the XPC service itself does not validate an incoming connection, any application installed on the operating system can send it XPC messages. In the case of the "connect" message, an attacker could manipulate the `OpenVPNPath` to point at a malicious binary on the system. The `com.ipvanish.osx.vpnhelper` would receive the VPNHelperConnect command, and then execute the malicious binary as the root user.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ipvanish | Ipvanish | 3.0.11 |
References
- https://github.com/VerSprite/research/blob/master/advisories/VS-2018-020.mdThird Party Advisory
- https://github.com/VerSprite/research/blob/master/advisories/VS-2018-020.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10192?
How severe is CVE-2018-10192?
How do I fix CVE-2018-10192?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-10187In radare2 2.5.0, there is a heap-based buffer over-read in …
- CVE-2018-10188phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attack…
- CVE-2018-10189An issue was discovered in Mautic 1.x and 2.x before 2.13.0.…
- CVE-2018-1019A remote code execution vulnerability exists in the way that…
- CVE-2018-10190A vulnerability in London Trust Media Private Internet Acces…
- CVE-2018-10191In versions of mruby up to and including 1.4.0, an integer o…9.8
- CVE-2018-10193LogMeIn LastPass through 4.15.0 allows remote attackers to c…
- CVE-2018-10194The set_text_distance function in devices/vector/gdevpdts.c …
- CVE-2018-10195lrzsz before version 0.12.21~rc can leak information to the …7.1
- CVE-2018-10196NULL pointer dereference vulnerability in the rebuild_vlists…
- CVE-2018-10197There is a time-based blind SQL injection vulnerability in t…
- CVE-2018-10198An issue was discovered in OTRS 6.0.x before 6.0.7. An attac…
Are you affected by CVE-2018-10192?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
