Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5013

Опубликовано: 24 окт. 2019
Источник: nvd
CVSS3: 7.1
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLaunchDProcess command. The command takes a user-supplied string argument and executes launchctl under root context. A user with local access can use this vulnerability to raise load arbitrary launchD agents. An attacker would need local access to the machine for a successful exploit.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:wacom:driver:6.3.32-3:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00135
Низкий

7.1 High

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-88
CWE-88

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLaunchDProcess command. The command takes a user-supplied string argument and executes launchctl under root context. A user with local access can use this vulnerability to raise load arbitrary launchD agents. An attacker would need local access to the machine for a successful exploit.

EPSS

Процентиль: 34%
0.00135
Низкий

7.1 High

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-88
CWE-88