peter bassill · operator
$ cve CVE-2018-18859 JSON

CVE-2018-18859 EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the value of the "tun_path" or "tap_path" pathname in a kextload() call.

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS1.57% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2018-11-20
Last modified2026-06-17

Affected (1)

VendorProduct
liquidvpnliquidvpn

Public exploits

SourceTitleDate
exploit-dbLiquidVPN 1.36 / 1.37 - Privilege Escalation2018-11-05

References

→ the Explorer  ·  watch your stack  ·  NVD