CVE-2018-18255: Capmon Access Manager

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in CapMon Access Manager 5.4.1.1005. The client applications of AccessManagerCoreService.exe communicate with this server through named pipes. A user can initiate communication with the server by creating a named pipe and sending commands to achieve elevated privileges.

Affected products

  • Capmon Access Manager: up to and including 5.4.1.1005

Published 2019-03-15. Last modified 2026-06-17.