CVE-2018-6823

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/02/2018
Last modified:
11/05/2020

Description

In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mailbutler:shimo:*:*:*:*:*:macos:*:* 4.1.5.1 (excluding)