CVE-2018-18603: Medium severity virustotal vulnerability

Published Oct 23, 2018
·
Updated

DISPUTED 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue.

Affected Software

1 affected component
360totalsecurity 360 Total Security=3.5.0.1033

Event History

Oct 23, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Disputed
04:29 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-18603?

CVE-2018-18603 is considered a disputed security-related issue that involves a potential sandbox escape.

2

How do I fix CVE-2018-18603?

As there is no official patch or fix available for CVE-2018-18603, users are advised to limit the execution of Python scripts in 360 Total Security.

3

What software version is affected by CVE-2018-18603?

CVE-2018-18603 affects version 3.5.0.1033 of 360 Total Security.

4

Is CVE-2018-18603 classified as a vulnerability by the vendor?

The vendor of 360 Total Security does not classify CVE-2018-18603 as a vulnerability, despite its security implications.

5

What type of attack is involved in CVE-2018-18603?

CVE-2018-18603 involves a potential sandbox escape through the use of Python's os module to execute system commands.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203