July 20, 2023, 6:25 p.m. |

CERT Recently Published Vulnerability Notes kb.cert.org

Overview


A command injection vulnerability can be used in the Perimeter81 macOS application to run arbitrary commands with administrative privileges.


Description


At the time, the latest Perimeter81 MacOS application (10.0.0.19) suffers from local privilege escalation vulnerability inside its com.perimeter81.osx.HelperTool. This HelperTool allows main application to setup things which require administrative privileges such as VPN connection, changing routing table, etc.


By combining insufficient checks of an XPC connection and creating a dictionary with the key "usingCAPath" a command can be appended …

administrative privileges application command command injection escalation injection latest local local privilege escalation macos main osx perimeter81 privilege privilege escalation privileges run things vpn vulnerabilities vulnerability

More from kb.cert.org / CERT Recently Published Vulnerability Notes

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)