CVE-2018-18857
HIGHLiquidVPN < 1.37 - Unauthenticated OS Command Injection via XPC Service
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-18857. PoCs published by Bernd Leitner.
AI-analyzed exploit summary The exploit demonstrates multiple privilege escalation vulnerabilities in LiquidVPN for macOS via an XPC service that fails to filter incoming messages. It includes PoC code for arbitrary command execution, command injection, and loading arbitrary kernel extensions.
Description
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "command_line" parameter as a shell command.
Exploits (1)
The exploit demonstrates multiple privilege escalation vulnerabilities in LiquidVPN for macOS via an XPC service that fails to filter incoming messages. It includes PoC code for arbitrary command execution, command injection, and loading arbitrary kernel extensions.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H