Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-94g5-26f2-52x8

Опубликовано: 02 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

The Automox Agent installation package before 37 on macOS allows an unprivileged user to obtain root access because of incorrect access control on a file used within the PostInstall script.

The Automox Agent installation package before 37 on macOS allows an unprivileged user to obtain root access because of incorrect access control on a file used within the PostInstall script.

EPSS

Процентиль: 25%
0.00085
Низкий

7 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7
nvd
больше 3 лет назад

Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process.

EPSS

Процентиль: 25%
0.00085
Низкий

7 High

CVSS3

Дефекты

CWE-367