LiveActive security incident?Get immediate response
CVE Record

CVE-2018-18253: An issue was discovered in CapMon Access Manager 5.4.1.1005.

An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe attempts to enforce access control by adding an unprivileged user to the local Administrators group for a very short time to execute a single command. However, the user is left in that group if the command crashes, and there is also a race condition in all cases.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This issue can turn a temporary administrative action into lasting local administrator access. CapMon Access Manager 5.4.1.1005 briefly adds a low-privileged user to Administrators, but failures and timing issues can leave that access behind.

Executive priority

Prioritize review where CapMon Access Manager is used on sensitive workstations or servers. The business risk is unauthorized local admin access, but urgency is tempered by limited public evidence on exploitation and fixes.

Technical view

CALRunElevated.exe grants temporary local Administrators membership to run one command. If the command crashes, the user remains in the group. The CVE description also reports a race condition in all cases, creating local privilege escalation risk.

Likely exposure

Exposure appears limited to systems running CapMon Access Manager 5.4.1.1005, particularly where CALRunElevated.exe is present or used for delegated elevated command execution.

Exploitation context

The source bundle does not show CISA KEV listing, active exploitation, public exploit status, CVSS, or named patch details. Treat this as a local privilege escalation weakness with incomplete public remediation evidence.

Researcher notes

Key unknowns are vendor patch status, exploit prevalence, exact trigger conditions, and affected version range beyond 5.4.1.1005. Do not broaden affected products without additional evidence.

Mitigation direction

  • Inventory systems running CapMon Access Manager 5.4.1.1005.
  • Check vendor or maintainer guidance for supported fixed versions.
  • Restrict who can invoke CALRunElevated.exe workflows.
  • Monitor local Administrators group membership changes.
  • Disable affected elevated-run workflows where business permits.

Validation and detection

  • Confirm whether CapMon Access Manager 5.4.1.1005 is installed.
  • Search managed endpoints for CALRunElevated.exe.
  • Audit local Administrators group membership for unexpected users.
  • Review logs for failed or crashed elevated command runs.
  • Validate remediation against vendor guidance when available.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-18253 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.