CVE-2018-6516: Puppet Enterprise Client Tools

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation.

Affected products

  • Puppet Puppet Enterprise Client Tools: from 16.4.0, before 16.4.6 (fixed in 16.4.6); from 17.3.0, before 17.3.6 (fixed in 17.3.6); from 18.1.0, before 18.1.2 (fixed in 18.1.2)

Published 2018-06-14. Last modified 2026-06-17.