CVE-2018-18860: Switchvpn
High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.
A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-permissive configuration settings and a SUID binary, an attacker is able to execute arbitrary binaries as root.
Affected products
- Switchvpn Switchvpn: version 2.1012.03 only
Published 2018-11-30. Last modified 2026-06-17.