CVE-2018-18858
Last modified
CVE-2018-18858 is a vulnerability of currently unknown severity. Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "tun_path" or "tap_path" pathname within a shell command.. EPSS estimates a 1.57% chance of exploitation in the next 30 days.
Description
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "tun_path" or "tap_path" pathname within a shell command.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Liquidvpn | Liquidvpn | <= 1.37 |
References
- http://packetstormsecurity.com/files/150137/LiquidVPN-For-macOS-1.3.7-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Nov/1Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/45782/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/150137/LiquidVPN-For-macOS-1.3.7-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Nov/1Exploit, Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/45782/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18858?
How severe is CVE-2018-18858?
How do I fix CVE-2018-18858?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18850In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1,…
- CVE-2018-18852Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command …
- CVE-2018-18853Lightbend Spray spray-json through 1.3.4 allows remote attac…
- CVE-2018-18854Lightbend Spray spray-json through 1.3.4 allows remote attac…
- CVE-2018-18856Multiple local privilege escalation vulnerabilities have bee…
- CVE-2018-18857Multiple local privilege escalation vulnerabilities have bee…
- CVE-2018-18859Multiple local privilege escalation vulnerabilities have bee…
- CVE-2018-1886IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.…5.3
- CVE-2018-18860A local privilege escalation vulnerability has been identifi…
- CVE-2018-18861Buffer overflow in PCMan FTP Server 2.0.7 allows for remote …
- CVE-2018-18862BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR …
- CVE-2018-18863NGA ResourceLink 20.0.2.1 allows local file inclusion.
Are you affected by CVE-2018-18858?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
