CVE-2018-4009

HIGH

Shimovpn Shimo VPN - Download Without Integrity Check

Title source: rule
STIX 2.1

Description

An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine to successfully exploit this bug.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 5.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-494
Status published
Products (1)
shimovpn/shimo_vpn 4.1.5.1
Published Apr 15, 2019
Tracked Since Feb 18, 2026