Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qx8f-vrc4-xhj5

Опубликовано: 01 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

EPSS

Процентиль: 2%
0.00014
Низкий

7.8 High

CVSS3

Дефекты

CWE-276
CWE-284

Связанные уязвимости

CVSS3: 7.8
nvd
2 месяца назад

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

EPSS

Процентиль: 2%
0.00014
Низкий

7.8 High

CVSS3

Дефекты

CWE-276
CWE-284