CVE-2018-5731
Last modified
CVE-2018-5731 is a vulnerability of currently unknown severity. An issue was discovered in Heimdal PRO 2.2.190. As part of the scanning feature, a process called md.hs writes an executable called CS1.tmp to C:\windows\TEMP. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
An issue was discovered in Heimdal PRO 2.2.190. As part of the scanning feature, a process called md.hs writes an executable called CS1.tmp to C:\windows\TEMP. Afterwards the executable is run. It is possible for an attacker to create the file first, let md.hs overwrite it, and then rewrite the file in the window between md.hs closing the file and executing it. This can be exploited via opportunistic locks and a high priority thread. The vulnerability is triggered when a scan starts. NOTE: any affected Heimdal products are completely unrelated to the Heimdal vendor of a Kerberos 5 product on the h5l.org web site.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Heimdalsecurity | Heimdal | 2.2.190 |
References
- https://improsec.com/blog/heimdal-advisory-2Exploit, Third Party Advisory
- https://improsec.com/blog/heimdal-advisory-2Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5731?
How severe is CVE-2018-5731?
How do I fix CVE-2018-5731?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5725MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated C…
- CVE-2018-5726MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers …
- CVE-2018-5727In OpenJPEG 2.3.0, there is an integer overflow vulnerabilit…
- CVE-2018-5728Cobham Sea Tel 121 build 222701 devices allow remote attacke…
- CVE-2018-5729MIT krb5 1.6 or later allows an authenticated kadmin with pe…4.7
- CVE-2018-5730MIT krb5 1.6 or later allows an authenticated kadmin with pe…3.8
- CVE-2018-5732Failure to properly bounds-check a buffer used for processin…7.5
- CVE-2018-5733A malicious client which is allowed to send very large amoun…7.5
- CVE-2018-5734While handling a particular type of malformed packet BIND er…7.5
- CVE-2018-5735The Debian backport of the fix for CVE-2017-3137 leads to as…7.5
- CVE-2018-5736An error in zone database reference counting can lead to an …
- CVE-2018-5737A problem with the implementation of the new serve-stale fea…5.9
Are you affected by CVE-2018-5731?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
