8.1
CVSSv3

CVE-2018-9859

Published: 16/06/2018 Updated: 03/10/2019
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The path of Whale update service was unquoted in NAVER Whale prior to 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications.

Vulnerable Product Search on Vulmon Subscribe to Product

navercorp whale