{"id":"CVE-2018-14438","details":"In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.","modified":"2026-07-08T17:57:44.467930Z","published":"2018-07-20T00:29:00.457Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/104876"},{"type":"REPORT","url":"https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14921"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wireshark/wireshark","events":[{"introduced":"0"},{"last_affected":"1b3cedbc5fe5b9d8b454a10fcd2046f0d38a9f19"}],"database_specific":{"cpe":"cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.6.2"}],"source":"CPE_RANGE"}}],"versions":["wireshark-2.6.2","v2.6.2","v2.6.2rc0","wireshark-2.6.1","v2.6.1","v2.6.1rc0","wireshark-2.6.0","v2.6.0","v2.6.0rc0","v2.5.2rc0","v2.5.1","v2.5.1rc0","wireshark-2.5.0","v2.5.0","v2.5.0rc0","v2.3.0rc0","v2.1.2rc0","wireshark-2.1.1","v2.1.1","v2.1.1rc0","wireshark-2.1.0","v2.1.0","v2.1.0rc0","v1.99.10rc0","wireshark-1.99.9","v1.99.9","v1.99.9rc0","wireshark-1.99.8","v1.99.8","v1.99.8rc0","wireshark-1.99.7","v1.99.7","v1.99.7rc0","wireshark-1.99.6","v1.99.6","v1.99.6rc0","wireshark-1.99.5","v1.99.5","v1.99.5rc0","wireshark-1.99.4","v1.99.4","v1.99.4rc0","wireshark-1.99.3","v1.99.3","v1.99.3rc0","wireshark-1.99.2","v1.99.2","v1.99.2rc0","wireshark-1.99.1","v1.99.1","v1.99.1rc0","wireshark-1.99.0","v1.99.0","v1.99.0-rc1","v1.11.4-rc1","wireshark-1.11.3","v1.11.3","v1.11.3-rc1","v1.11.2","v1.11.2-rc1","v1.11.1","v1.11.1-rc1","v1.11.0","v1.11.0-rc1","start","ethereal-0.3.15","ethereal-0-3-15","backups/ethereal@18706"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14438.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/wireshark/wireshark","events":[{"introduced":"0"},{"last_affected":"1b3cedbc5fe5b9d8b454a10fcd2046f0d38a9f19"}],"database_specific":{"cpe":"cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.6.2"}],"source":"CPE_RANGE"}}],"versions":["wireshark-2.6.2","v2.6.2","v2.6.2rc0","wireshark-2.6.1","v2.6.1","v2.6.1rc0","wireshark-2.6.0","v2.6.0","v2.6.0rc0","v2.5.2rc0","v2.5.1","v2.5.1rc0","wireshark-2.5.0","v2.5.0","v2.5.0rc0","v2.3.0rc0","v2.1.2rc0","wireshark-2.1.1","v2.1.1","v2.1.1rc0","wireshark-2.1.0","v2.1.0","v2.1.0rc0","v1.99.10rc0","wireshark-1.99.9","v1.99.9","v1.99.9rc0","wireshark-1.99.8","v1.99.8","v1.99.8rc0","wireshark-1.99.7","v1.99.7","v1.99.7rc0","wireshark-1.99.6","v1.99.6","v1.99.6rc0","wireshark-1.99.5","v1.99.5","v1.99.5rc0","wireshark-1.99.4","v1.99.4","v1.99.4rc0","wireshark-1.99.3","v1.99.3","v1.99.3rc0","wireshark-1.99.2","v1.99.2","v1.99.2rc0","wireshark-1.99.1","v1.99.1","v1.99.1rc0","wireshark-1.99.0","v1.99.0","v1.99.0-rc1","v1.11.4-rc1","wireshark-1.11.3","v1.11.3","v1.11.3-rc1","v1.11.2","v1.11.2-rc1","v1.11.1","v1.11.1-rc1","v1.11.0","v1.11.0-rc1","start","ethereal-0.3.15","ethereal-0-3-15","backups/ethereal@18706"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14438.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}