{"containers":{"cna":{"affected":[{"product":"uTorrent","vendor":"unspecified","versions":[{"status":"affected","version":"n/a"}]}],"credits":[{"lang":"en","value":"Tavis Ormandy"}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processing of the component Guest Account. The manipulation leads to privilege escalation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2022-06-17T04:45:36.000Z","orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB"},"references":[{"tags":["x_refsource_MISC"],"url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1524"},{"tags":["x_refsource_MISC"],"url":"http://www.math.sci.hiroshima-u.ac.jp/~m-mat/MT/efaq.html"},{"tags":["x_refsource_MISC"],"url":"https://vuldb.com/?id.113807"}],"title":"uTorrent Guest Account privileges management","x_generator":"vuldb.com","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cna@vuldb.com","ID":"CVE-2018-25044","REQUESTER":"cna@vuldb.com","STATE":"PUBLIC","TITLE":"uTorrent Guest Account privileges management"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"uTorrent","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":""}]}},"credit":"Tavis Ormandy","data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processing of the component Guest Account. The manipulation leads to privilege escalation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component."}]},"generator":"vuldb.com","impact":{"cvss":{"baseScore":"6.3","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-269 Improper Privilege Management"}]}]},"references":{"reference_data":[{"name":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1524","refsource":"MISC","url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1524"},{"name":"http://www.math.sci.hiroshima-u.ac.jp/~m-mat/MT/efaq.html","refsource":"MISC","url":"http://www.math.sci.hiroshima-u.ac.jp/~m-mat/MT/efaq.html"},{"name":"https://vuldb.com/?id.113807","refsource":"MISC","url":"https://vuldb.com/?id.113807"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T12:26:39.665Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1524"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.math.sci.hiroshima-u.ac.jp/~m-mat/MT/efaq.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://vuldb.com/?id.113807"}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-04-14T17:10:40.396342Z","id":"CVE-2018-25044","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-15T14:23:49.704Z"}}]},"cveMetadata":{"assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","assignerShortName":"VulDB","cveId":"CVE-2018-25044","datePublished":"2022-06-17T04:45:36.000Z","dateReserved":"2022-06-04T00:00:00.000Z","dateUpdated":"2025-04-15T14:23:49.704Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}