CVE-2018-6823

In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mailbutler:shimo:*:*:*:*:*:macos:*:*

History

21 Nov 2024, 04:11

Type Values Removed Values Added
References () https://github.com/VerSprite/research/blob/master/advisories/VS-2018-001.md - Third Party Advisory () https://github.com/VerSprite/research/blob/master/advisories/VS-2018-001.md - Third Party Advisory

Information

Published : 2018-02-07 16:29

Updated : 2024-11-21 04:11


NVD link : CVE-2018-6823

Mitre link : CVE-2018-6823

CVE.ORG link : CVE-2018-6823


JSON object : View

Products Affected

mailbutler

  • shimo