CVE-2018-18856
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.6%
from disclosure to weapon0 days
Published on NVDNov 20
1st PoCNov 5
exploitation probability
1.6%top 27% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "openvpncmd" parameter as a shell command.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/150137/LiquidVPN-For-macOS-1.3.7-Privilege-Escalation.htmlunverifiedcve_referencewww.exploit-db.com/exploits/45782/unverifiedexploitdbwww.exploit-db.com/exploits/45782unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.