{"api_version":"1","generated_at":"2026-07-23T06:38:37+00:00","cve":"CVE-2018-17488","urls":{"html":"https://cve.report/CVE-2018-17488","api":"https://cve.report/api/cve/CVE-2018-17488.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-17488","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-17488"},"summary":{"title":"CVE-2018-17488","description":"Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print badge screen, an attacker could exploit this vulnerability using the command line to break out of kiosk mode.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-03-21 16:00:00","updated_at":"2019-10-09 23:36:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/149648","name":"lobby-track-cve201817488-priv-esc (149648)","refsource":"XF","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-17488","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-17488","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"17488","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jollytech","cpe5":"lobby_track","cpe6":"8.2.186","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"desktop","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"17488","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jollytech","cpe5":"lobby_track","cpe6":"8.2.186","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"desktop","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print badge screen, an attacker could exploit this vulnerability using the command line to break out of kiosk mode."}]},"references":{"reference_data":[{"title":"X-Force Vulnerability Report","name":"lobby-track-cve201817488-priv-esc (149648)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/149648"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Gain Privileges"}]}]},"data_type":"CVE","CVE_data_meta":{"STATE":"PUBLIC","ID":"CVE-2018-17488","DATE_PUBLIC":"2019-03-04T00:00:00","ASSIGNER":"psirt@us.ibm.com"},"data_format":"MITRE","impact":{"cvssv3":{"BM":{"UI":"N","S":"U","AV":"L","A":"H","PR":"N","I":"H","SCORE":"8.400","AC":"L","C":"H"},"TM":{"E":"U","RL":"U","RC":"R"}}},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Jolly Technologies","product":{"product_data":[{"version":{"version_data":[{"version_value":"8.2.186"}]},"product_name":"Lobby Track Desktop"}]}}]}}},"nvd":{"publishedDate":"2019-03-21 16:00:00","lastModifiedDate":"2019-10-09 23:36:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jollytech:lobby_track:8.2.186:*:*:*:desktop:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"17488","Ordinal":"134301","Title":"CVE-2018-17488","CVE":"CVE-2018-17488","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"17488","Ordinal":"1","NoteData":"Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print badge screen, an attacker could exploit this vulnerability using the command line to break out of kiosk mode.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"17488","Ordinal":"2","NoteData":"2019-03-19","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"17488","Ordinal":"3","NoteData":"2019-03-19","Type":"Other","Title":"Modified"}]}}}