CVE-2018-9105
CVE-2018-9105 is a high-severity vulnerability in Nordvpn with a CVSS 3.x base score of 8.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- CVSS v2: 9.0
- EPSS exploit prediction: 3% (85th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Nordvpn
- Published:
- Last modified:
Description
NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemented XPC service. This XPC service is responsible for receiving and processing new OpenVPN connection requests from the main application. Unfortunately this XPC service is not protected, which allows arbitrary applications to connect and send it XPC messages. An attacker can send a crafted XPC message to the privileged helper tool requesting it make a new OpenVPN connection. Because he or she controls the contents of the XPC message, the attacker can specify the location of the openvpn executable, which could point to something malicious they control located on disk. Without validation of the openvpn executable, this will give the attacker code execution in the context of the privileged helper tool.
Frequently asked questions
- What is CVE-2018-9105?
- NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemented XPC service. This XPC service is responsible for receiving and processing new OpenVPN connection requests from the main application. Unfortunately this XPC service is not protected, which allows arbitrary applications to connect and send it XPC messages. An attacker can send a crafted XPC message to the privileged helper tool requesting it make a new OpenVPN connection. Because he or she controls the contents of the XPC message, the attacker can specify the location of the openvpn executable, which could point to something malicious they control located on disk. Without validation of the openvpn executable, this will give the attacker code execution in the context of the privileged helper tool.
- How severe is CVE-2018-9105?
- CVE-2018-9105 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2018-9105 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (85th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-9105?
- CVE-2018-9105 affects Nordvpn. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2018-9105?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2018-9105 published?
- CVE-2018-9105 was published on 2018-03-27 and last updated on 2026-06-17.
References
- https://github.com/VerSprite/research/blob/master/advisories/VS-2018-015.md
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140939
Affected products (1)
- cpe:2.3:a:nordvpn:nordvpn:3.3.10:*:*:*:*:macos:*:*
More vulnerabilities in Nordvpn
- CVE-2018-10170 — Critical (CVSS 9.8): NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service"…
- CVE-2018-3952 — High (CVSS 8.8): An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially…
- CVE-2019-25572 — Medium (CVSS 6.2): NordVPN 6.19.6 contains a denial of service vulnerability that allows local attackers to crash the application by…
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →