Lucene search

K
cvelistVulDBCVELIST:CVE-2018-25041
HistoryJun 17, 2022 - 4:45 a.m.

CVE-2018-25041 uTorrent JSON RPC Server privileges management

2022-06-1704:45:32
CWE-269
VulDB
www.cve.org

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

8.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.3%

A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionality of the component JSON RPC Server. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

CNA Affected

[
  {
    "product": "uTorrent",
    "vendor": "unspecified",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

8.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.3%

Related for CVELIST:CVE-2018-25041