CVE-2018-18859 | LiquidVPN Client up to 1.37 on MacOS XPC Service kextload tun_path/tap_path os command injection (EDB-45782)
A vulnerability, which was classified as critical, was found in LiquidVPN Client up to 1.37 on MacOS. Affected is the function kextload of the component XPC Service. The manipulation of the argument tun_path/tap_path leads to os command injection.
This vulnerability is traded as CVE-2018-18859. Attacking locally is a requirement. Furthermore, there is an exploit available.