CVE-2018-25040

MEDIUM

uTorrent Web - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component HTTP RPC Server. The manipulation leads to privilege escalation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

References (3)

Core 3
Core References
Issue Tracking, Mailing List, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/project-zero/issues/detail?id=1524
Exploit, Third Party Advisory x_refsource_misc
https://vuldb.com/?id.113803

Scores

CVSS v3 6.3
EPSS 0.0085
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (1)
utorrent/web
Published Jun 17, 2022
Tracked Since Feb 18, 2026