CVE-2018-6516 is a high-severity vulnerability affecting Puppet PE client tools (pe-client-tools) on Windows, specifically versions 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2. An attacker could craft a malicious configuration file to achieve arbitrary code execution with privilege escalation. The attack requires user interaction (UI:R) but has low attack complexity (AC:L) and local access (AV:L), leading to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.4.0, < 16.4.6CPE matchmatch criteria | cpe:2.3:a:puppet:puppet_enterprise_client_tools:*:*:*:*:*:*:*:* | ||
>= 17.3.0, < 17.3.6CPE matchmatch criteria | cpe:2.3:a:puppet:puppet_enterprise_client_tools:*:*:*:*:*:*:*:* | ||
>= 18.1.0, < 18.1.2CPE matchmatch criteria | cpe:2.3:a:puppet:puppet_enterprise_client_tools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.