PT-2018-1124 · Cactusvpn · Cactusvpn

Benjamin Watson

+1

·

Published

2018-02-21

·

Updated

2021-09-22

·

CVE-2018-7493

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CactusVPN versions through 6.0 for macOS
Description The issue is related to the implementation of the XPC interface in the CactusVPN software, which is used to access the VPN service. This implementation has access control weaknesses. Exploitation of the issue can allow a remote attacker to execute system commands with root privileges. The privileged helper tool in CactusVPN implements an XPC interface, enabling arbitrary applications to execute system commands as root.
Recommendations For CactusVPN versions through 6.0 for macOS, consider disabling the privileged helper tool until a patch is available to prevent arbitrary applications from executing system commands as root. Restrict access to the XPC interface to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00549
CVE-2018-7493

Affected Products

Cactusvpn