Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgjc-79v8-mc48

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious application to the plugin directory, allowing the malicious application to execute in a privileged context.

All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious application to the plugin directory, allowing the malicious application to execute in a privileged context.

EPSS

Процентиль: 60%
0.00396
Низкий

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious application to the plugin directory, allowing the malicious application to execute in a privileged context.

EPSS

Процентиль: 60%
0.00396
Низкий

Дефекты

CWE-367