ZeroHour

CVE-2018-6823

CVSS 3.0
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root.

Vendors
mailbutler
Products
shimo
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.