ZeroHour
CyberScooppublished ()ingested @jeffstone500

Shimo VPN service contains six unpatched vulnerabilities, Talos discovers

criticalVulnerability exploited in the wildimportance 60CVE-2018-4004CVE-2018-4007

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-4007
+1 in the same advisory: …4004
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality.

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is able to delete any protected file on the system. An attacker would need local access to the machine to successfully exploit the bug.

NVD description · AI analysis pending
7.1
group max
<1% PoC
  • shimovpn shimo vpn
Full article711 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Details of the vulnerabilities were released after Cisco made “repeated attempts” to communicate with Shimo over 90 days to no avail, Talos said.

Shimo VPN
(Getty)

A series of vulnerabilities in virtual private network service Shimo’s Helper Tool, a popular app used to connect multiple VPNs for Mac operating systems, would make it possible for hackers to obtain root control, according to research published Monday by Cisco’s Talos research team.

Researchers detailed six vulnerabilities in the Shimo VPN Helper Tool that relies on to carry out its privileged work, according to a blog post. Details of the vulnerabilities were released after Cisco made “repeated attempts” to communicate with Shimo over 90 days to no avail, Talos said.

Shimo did not immediately respond to a request for comment from CyberScoop.

One vulnerability, listed as CVE-2018-4004, is a privilege escalation vulnerability that resides in the Shimo VPN helper’s disconnectService function, and would allow a “non-root user to kill privileged processes on the system.” Another, CVE-2018-4007, resides in the deleteConfig functionality and “could allow an attacker to delete any protected file on the system.” Shimo VPN version 4.1.5.1 is known to be vulnerable, according to Cisco.

All of the vulnerabilities listed require an attacker to have local access to a device. A complete list of vulnerabilities and technical details is available on Cisco’s Talos blog.

This disclosure comes after the U.S. Department of Homeland Security on Friday alerted the public to a flaw in multiple enterprise VPN apps that could give hackers access to other apps running on a VPN connection, as CyberScoop reported. The issue involves insecure cookie storage in memory or log files. DHS said the vulnerability was present in apps made by Cisco, F5 Networks, Palo Alto Networks and Pulse Secure, though Carnegie Mellon University’s CERT Coordination Center said other VPN apps likely were affected.

Users rely on VPNs to protect their location and shield their internet activity at times when they might be especially vulnerable. Hackers, by breaching VPNs, can exploit the trust users place in VPNs for their own gain, either to steal business secrets, conduct espionage or for other purposes.

Shimo is advertised as the “Fort Knox of VPNs” in part because the company follows the “highest security standards,” according to its website.

More Scoops

Sen. Ron Wyden, D-Ore., leaves a Senate Democratic meeting at the U.S. Capitol Building on Oct. 3, 2025. (Photo by Kevin Dietsch/Getty Images)

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech.

This photograph shows a laptop screen displaying the logo of the First VPN service website in Quimper on May 21, 2026. (Photo by Fred TANNEAU / AFP)

Treasury sanctions First VPN Service, others for abetting ransomware gangs

Europol, the European Union’s law enforcement agency, is pictured at its headquarters building on June 24, 2020 in The Hague, Netherlands. (Photo by Yuriko Nakao/Getty Images)

European authorities take down prolific cybercrime VPN service

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/shimo-vpn-vulnerabilities-cisco-talos/