Описание
BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool implements an XPC interface that allows file operations to any process (copy, move, delete) as root and changing permissions.
Ссылки
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.0 (включая) до 3.4 (исключая)
cpe:2.3:a:binarynights:forklift:*:*:*:*:*:macos:*:*
EPSS
Процентиль: 40%
0.00186
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-862
Связанные уязвимости
github
больше 3 лет назад
BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool implements an XPC interface that allows file operations to any process (copy, move, delete) as root and changing permissions.
EPSS
Процентиль: 40%
0.00186
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-862