VULNERABILITY INTELLIGENCE
CVE-2018-17491
CVSS score8.4 HIGH
EPSS probability0.34%
CISA KEVNot currently listed
Published2019-03-21
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized actions on the computer.
Weakness classification
- CWE-862: Missing Authorization
Primary references
- psirt@us.ibm.com — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry