← back
CVE-2018-18858

CVE-2018-18858

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.6%
from disclosure to weapon0 days
Published on NVDNov 20
1st PoCNov 5
exploitation probability
1.6%top 27% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "tun_path" or "tap_path" pathname within a shell command.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.