CVE-2018-9859: High severity Navercorp Whale vulnerability
The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NAVER Whale update serviceto a version that resolves this vulnerability.Fixed in 1.0.40.7 - Compensating control
Prevent other vulnerable applications from creating or placing executables that Whale update service could later run with System privilege (e.g., restrict such file creation/launch capabilities via host hardening/containment).
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9859?
CVE-2018-9859 is considered to have a high severity due to its potential for privilege escalation.
How do I fix CVE-2018-9859?
To fix CVE-2018-9859, update Naver Whale to version 1.0.40.7 or later.
What type of vulnerability is CVE-2018-9859?
CVE-2018-9859 is classified as an unquoted service path vulnerability.
Who is affected by CVE-2018-9859?
CVE-2018-9859 affects all versions of Naver Whale before 1.0.40.7.
Can CVE-2018-9859 lead to remote code execution?
CVE-2018-9859 can lead to a local privilege escalation but does not directly enable remote code execution.