CVE-2018-18603
6.3
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 4.0
Source: NVD
Description
360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue
Affected (1)
Products: 360totalsecurity: 360 Total Security
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.5.0.1033 |
References (3)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.