Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4j83-7cvp-5r59

Опубликовано: 25 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.

The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.

EPSS

Процентиль: 9%
0.00033
Низкий

7.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.8
nvd
около 1 года назад

The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.

EPSS

Процентиль: 9%
0.00033
Низкий

7.8 High

CVSS3

Дефекты

CWE-862