peter bassill · operator
$ cve CVE-2018-16518 JSON

CVE-2018-16518

9.8
CRITICAL · CVSS 3.0 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrary files on a user's workstation using crafted ZED! containers because the watermark loading function can place an executable file into a Startup folder.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.24% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2018-09-05
Last modified2026-06-17

Affected (2)

VendorProduct
primxzed\!
primxzed\! free

References

→ the Explorer  ·  watch your stack  ·  NVD