Описание
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.
Ссылки
- Issue TrackingPatch
- ExploitPatchVendor Advisory
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.16.0 (исключая)
Одновременно
cpe:2.3:a:canonical:multipass:*:-:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00012
Низкий
7.3 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-276
CWE-863
Связанные уязвимости
CVSS3: 7.3
ubuntu
около 2 месяцев назад
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.
EPSS
Процентиль: 1%
0.00012
Низкий
7.3 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-276
CWE-863