Remote Code Execution in CyberArk Password Vault Web Access
CVE-2018-9843
Key Information:
- Vendor
Cyberark
- Status
- Vendor
- CVE Published:
- 12 April 2018
Badges
What is CVE-2018-9843?
The REST API of CyberArk Password Vault Web Access versions prior to 9.9.5 and 10.x below 10.1 is susceptible to a remote code execution vulnerability. This flaw allows remote attackers to inject and execute arbitrary code by sending a specially crafted serialized .NET object in an Authorization HTTP header. Exploitation of this vulnerability could lead to unauthorized access and potentially compromise the security of the system.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
