CVE-2018-18603: Medium severity virustotal vulnerability
DISPUTED 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18603?
CVE-2018-18603 is considered a disputed security-related issue that involves a potential sandbox escape.
How do I fix CVE-2018-18603?
As there is no official patch or fix available for CVE-2018-18603, users are advised to limit the execution of Python scripts in 360 Total Security.
What software version is affected by CVE-2018-18603?
CVE-2018-18603 affects version 3.5.0.1033 of 360 Total Security.
Is CVE-2018-18603 classified as a vulnerability by the vendor?
The vendor of 360 Total Security does not classify CVE-2018-18603 as a vulnerability, despite its security implications.
What type of attack is involved in CVE-2018-18603?
CVE-2018-18603 involves a potential sandbox escape through the use of Python's os module to execute system commands.