CVE-2018-16097
LXCI for VMware and LXCI for Microsoft System Center
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 Nov 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →