CVE-2018-17487 is a high-severity privilege escalation vulnerability affecting Jolly Technologies Lobby Track Desktop. A local attacker can exploit an error in the printer dialog to break out of kiosk mode and gain elevated system privileges. With a CVSS score of 7.8, this vulnerability is easily exploitable with low attack complexity and no user interaction, leading to high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, and it's not listed in the KEV catalog, there has been some community discussion and media coverage, indicating awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.2.186CPE matchmatch criteria | cpe:2.3:a:jollytech:lobby_track:8.2.186:*:*:*:desktop:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.