CVE-2018-14894: High severity cyberark endpoint privilege manager vulnerability
Published Apr 9, 2019
·Updated
CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access restrictions and execute blocked applications.
Affected Software
1 affected component
CyberArk Endpoint Privilege Manager<=10.2.1.603
Event History
Apr 9, 2019
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
Description
Frequently Asked Questions
1
What is CVE-2018-14894?
CVE-2018-14894 is a vulnerability in CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier that allows an attacker to bypass access restrictions and execute blocked applications.
2
How severe is CVE-2018-14894?
CVE-2018-14894 has a severity rating of 7.8 (high).
3
How does CVE-2018-14894 work?
CVE-2018-14894 allows an attacker, who can edit permissions of a file, to bypass intended access restrictions and execute blocked applications.
4
What software versions are affected by CVE-2018-14894?
CyberArk Endpoint Privilege Manager versions up to and including 10.2.1.603 are affected by CVE-2018-14894.
5
Are there any known exploits for CVE-2018-14894?
Yes, there are known exploits available for CVE-2018-14894.