CVE-2018-6516

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/06/2018
Last modified:
03/10/2019

Description

On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:puppet:puppet_enterprise_client_tools:*:*:*:*:*:*:*:* 16.4.0 (including) 16.4.6 (excluding)
cpe:2.3:a:puppet:puppet_enterprise_client_tools:*:*:*:*:*:*:*:* 17.3.0 (including) 17.3.6 (excluding)
cpe:2.3:a:puppet:puppet_enterprise_client_tools:*:*:*:*:*:*:*:* 18.1.0 (including) 18.1.2 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools