← Back

CVE-2018-6515

nvd nist
Published: Jun 11, 2018Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.

Affected (3)

Products: Puppet: Puppet
1 product
Puppet
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Puppet
From 1.10.0 to 1.10.13
From 5.3.0 to 5.3.7
From 5.5.0 to 5.5.2
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Source: security@puppet.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.