CVE-2018-7281

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/02/2018
Last modified:
04/05/2020

Description

CactusVPN 5.3.6 for macOS contains a root privilege escalation vulnerability through a setuid root binary called runme. The binary takes a single command line argument and passes this argument to a system() call, thus allowing low privileged users to execute commands as root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cactusvpn:cactusvpn:5.3.6:*:*:*:*:macos:*:*