CVE-2018-6823: Mailbutler Shimo
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root.
Affected products
- Mailbutler Shimo: before 4.1.5.1 (fixed in 4.1.5.1)
Published 2018-02-07. Last modified 2026-06-17.