{"api_version":"1","generated_at":"2026-07-23T04:56:43+00:00","cve":"CVE-2018-4041","urls":{"html":"https://cve.report/CVE-2018-4041","api":"https://cve.report/api/cve/CVE-2018-4041.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-4041","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-4041"},"summary":{"title":"CVE-2018-4041","description":"An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.","state":"PUBLIC","assigner":"talos-cna@cisco.com","published_at":"2019-01-10 15:29:00","updated_at":"2022-06-07 17:16:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0715","name":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0715","refsource":"MISC","tags":["Third Party Advisory"],"title":"TALOS-2018-0715 ||  Cisco Talos Intelligence Group - Comprehensive Threat Intelligence","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-4041","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-4041","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"4041","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macpaw","cpe5":"cleanmymac_x","cpe6":"4.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"4041","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macpaw","cpe5":"cleanmymac_x","cpe6":"4.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"talos-cna@cisco.com","ID":"CVE-2018-4041","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Clean My Mac","version":{"version_data":[{"version_value":"Clean My Mac X 4.04"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Input Validation"}]}]},"references":{"reference_data":[{"name":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0715","refsource":"MISC","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0715"}]},"impact":{"cvss":{"baseScore":7.1,"baseSeverity":"High","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","version":"3.0"}}},"nvd":{"publishedDate":"2019-01-10 15:29:00","lastModifiedDate":"2022-06-07 17:16:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:C/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"COMPLETE","availabilityImpact":"NONE","baseScore":4.9},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:macpaw:cleanmymac_x:4.04:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"4041","Ordinal":"119955","Title":"CVE-2018-4041","CVE":"CVE-2018-4041","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"4041","Ordinal":"1","NoteData":"An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"4041","Ordinal":"2","NoteData":"2019-01-10","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"4041","Ordinal":"3","NoteData":"2019-01-10","Type":"Other","Title":"Modified"}]}}}