PT-2018-18611 · Keepsolid · Vpn Unlimited
Benjamin Watson
+1
·
Published
2018-03-16
·
Updated
2019-10-03
·
CVE-2018-8739
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VPN Unlimited version 4.2.0 for macOS
Description
The issue concerns a root privilege escalation in the privileged helper tool of VPN Unlimited. This tool implements an XPC interface, allowing arbitrary applications to execute system commands as root.
Recommendations
For VPN Unlimited version 4.2.0, consider disabling the XPC interface in the privileged helper tool until a patch is available to prevent arbitrary system command execution as root.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vpn Unlimited