CVE-2018-6336

HIGH

Linuxfoundation Osquery < 3.2.7 - Security Feature Bypass

Title source: rule
STIX 2.1

Description

An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute. This issue affects osquery prior to v3.2.7

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 26.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-254 CWE-354
Status published
Products (1)
linuxfoundation/osquery < 3.2.7
Published Dec 31, 2018
Tracked Since Feb 18, 2026