CVE-2018-5511

HIGH

F5 BIG-IP <13.1.0.3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-5511. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit leverages a process impersonation vulnerability in VMware Workstation/Player on Windows, allowing a non-admin user to hijack the VMX process creation by replacing the executable path via drive letter manipulation. The fake VMX process can then use privileged commands like 'opensecurable' to escalate privileges to SYSTEM.

Description

On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textlocalwindows
https://www.exploit-db.com/exploits/46600

This exploit leverages a process impersonation vulnerability in VMware Workstation/Player on Windows, allowing a non-admin user to hijack the VMX process creation by replacing the executable path via drive letter manipulation. The fake VMX process can then use privileged commands like 'opensecurable' to escalate privileges to SYSTEM.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: VMware Workstation Windows v14.1.5, VMware Player 15.0.2
No auth needed
Prerequisites: Non-admin user access on Windows host · VMware Workstation/Player installed · Ability to replace drive letter mappings
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K30500703
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46600/

Scores

CVSS v3 7.2
EPSS 0.1494
EPSS Percentile 96.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-470
Status published
Products (29)
f5/big-ip_access_policy_manager 13.0.0
f5/big-ip_access_policy_manager 13.1.0
f5/big-ip_advanced_firewall_manager 13.0.0
f5/big-ip_advanced_firewall_manager 13.1.0
f5/big-ip_analytics 13.0.0
f5/big-ip_analytics 13.1.0
f5/big-ip_application_acceleration_manager 13.0.0
f5/big-ip_application_acceleration_manager 13.1.0
f5/big-ip_application_security_manager 13.0.0
f5/big-ip_application_security_manager 13.1.0
... and 19 more
Published Apr 13, 2018
Tracked Since Feb 18, 2026