PT-2019-10748 · Feingeist · Shimo Vpn

CVE-2018-4008

·

Publicado

2019-04-15

·

Atualizado

2023-02-02

CVSS v3.1

9.3

Crítica

VetorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shimo VPN version 4.1.5.1
Description A privilege escalation issue exists in the Shimo VPN helper service, specifically in the RunVpncScript command. This command executes a user-supplied script argument under root context, allowing a user with local access to raise their privileges to root. An attacker would need local access to the machine to successfully exploit this issue.
Recommendations For Shimo VPN version 4.1.5.1, consider disabling the RunVpncScript command until a patch is available to prevent exploitation. Restrict access to the helper service to minimize the risk of privilege escalation. Avoid using the script argument in the RunVpncScript command until the issue is resolved.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-4008

Produtos afetados

Shimo Vpn