CVE-2018-18857
Last modified
CVE-2018-18857 is a vulnerability of currently unknown severity. Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "command_line" parameter as a shell command.. EPSS estimates a 1.60% chance of exploitation in the next 30 days.
Description
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "command_line" parameter as a shell command.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Liquidvpn | Liquidvpn | <= 1.37 |
References
- http://packetstormsecurity.com/files/150137/LiquidVPN-For-macOS-1.3.7-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Nov/1Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/45782/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/150137/LiquidVPN-For-macOS-1.3.7-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Nov/1Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/45782/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18857?
How severe is CVE-2018-18857?
How do I fix CVE-2018-18857?
Are you affected by CVE-2018-18857?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
