6.8
CVSSv2

CVE-2018-6515

Published: 11/06/2018 Updated: 02/08/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Puppet Agent 1.10.x before 1.10.13, Puppet Agent 5.3.x before 5.3.7, and Puppet Agent 5.5.x before 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet

Vendor Advisories

Puppet Agent 110x prior to 11013, Puppet Agent 53x prior to 537, and Puppet Agent 55x prior to 552 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation ...