Record summary

CVE-2018-16167 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 15, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List1.2.0 and earlieraffected
VulnCheckVersion data not supplied

Proofs of concept

2

Catalogued exploits

ExploitDBLogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)ExploitDB exploitby g0ldm45kNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubdnr6419/CVE-2018-16167Repository PoCby dnr6419Stars: 0Not analyzed2 files

2.8 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALLogonTracer <=1.2.0 - Remote Command InjectionCVSS 9.8

LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Impact

Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.

Remediation

Upgrade LogonTracer to a version higher than 1.2.0.

WeaknessesCWE-78
Authorsgy741
Template tagscvecve2018rceoastedblogontracerintrusivejpcertvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:jpcert:logontracer:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3