Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qqr-wg3h-jf3m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.

An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.

EPSS

Процентиль: 74%
0.00802
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.1
nvd
больше 5 лет назад

An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.

EPSS

Процентиль: 74%
0.00802
Низкий

Дефекты

CWE-20