Back to search
CVE-2018-6516
Published: Jun 14, 2018
Modified: Sep 16, 2024
PUBLISHED
Description
On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation.
| Vendor | Product | Versions |
|---|---|---|
Puppet | pe-client-tools | affected 16.4.x prior to 16.4.6affected 17.3.x prior to 17.3.6affected 18.1.x prior to 18.1.2 |
References
https://puppet.com/security/cve/CVE-2018-6516
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now