CVE-2018-19788

HIGH

PolicyKit <0.115 - Privilege Escalation

Title source: llm

Description

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

Exploits (5)

nomisec WORKING POC 19 stars
by Ekultek · poc
https://github.com/Ekultek/PoC
nomisec WORKING POC 5 stars
by AbsoZed · poc
https://github.com/AbsoZed/CVE-2018-19788
nomisec WORKING POC 3 stars
by d4gh0s7 · poc
https://github.com/d4gh0s7/CVE-2018-19788
nomisec WORKING POC 1 stars
by jhlongjr · poc
https://github.com/jhlongjr/CVE-2018-19788
gitlab WORKING POC
by hyperd · poc
https://gitlab.com/hyperd/ansible-role-cve-2018-19788

Scores

CVSS v3 8.8
EPSS 0.5964
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (8)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
debian/debian_linux 8.0
debian/debian_linux 9.0
polkit_project/polkit 0.115
Published Dec 03, 2018
Tracked Since Feb 18, 2026