VulnerabilityModified
CVE-2018-18629
An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.
HIGH 7.8EPSS 1.49%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-426
- Affected
- keybase/keybase
- Source
- cve@mitre.org
References
- https://blog.mirch.io/2018/12/21/cve-2018-18629-keybase-linux-privilege-escalation/Exploit, Third Party Advisory
- https://hackerone.com/reports/426944Exploit, Patch, Third Party Advisory
- https://keybase.io/docs/secadv/kb002Exploit, Vendor Advisory
- https://blog.mirch.io/2018/12/21/cve-2018-18629-keybase-linux-privilege-escalation/Exploit, Third Party Advisory
- https://hackerone.com/reports/426944Exploit, Patch, Third Party Advisory
- https://keybase.io/docs/secadv/kb002Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.