PT-2018-1124 · Cactusvpn · Cactusvpn

Benjamin Watson

+1

·

Publicado

2018-02-21

·

Atualizado

2021-09-22

·

CVE-2018-7493

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CactusVPN versions through 6.0 for macOS
Description The issue is related to the implementation of the XPC interface in the CactusVPN software, which is used to access the VPN service. This implementation has access control weaknesses. Exploitation of the issue can allow a remote attacker to execute system commands with root privileges. The privileged helper tool in CactusVPN implements an XPC interface, enabling arbitrary applications to execute system commands as root.
Recommendations For CactusVPN versions through 6.0 for macOS, consider disabling the privileged helper tool until a patch is available to prevent arbitrary applications from executing system commands as root. Restrict access to the XPC interface to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00549
CVE-2018-7493

Produtos afetados

Cactusvpn