Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-656v-64rf-6vxr

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.

iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.

EPSS

Процентиль: 2%
0.00013
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-428

Связанные уязвимости

CVSS3: 7.8
nvd
24 дня назад

iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.

EPSS

Процентиль: 2%
0.00013
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-428