July 20, 2023, 6:25 p.m. |

CERT Recently Published Vulnerability Notes kb.cert.org

Overview


A command injection vulnerability can be used in the Perimeter81 macOS application to run arbitrary commands with administrative privileges.


Description


At the time, the latest Perimeter81 MacOS application (10.0.0.19) suffers from local privilege escalation vulnerability inside its com.perimeter81.osx.HelperTool. This HelperTool allows main application to setup things which require administrative privileges such as VPN connection, changing routing table, etc.


By combining insufficient checks of an XPC connection and creating a dictionary with the key "usingCAPath" a command can be appended …

administrative privileges application command command injection escalation injection latest local local privilege escalation macos main osx perimeter81 privilege privilege escalation privileges run things vpn vulnerabilities vulnerability

More from kb.cert.org / CERT Recently Published Vulnerability Notes

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Data Privacy Manager m/f/d)

@ Coloplast | Hamburg, HH, DE

Cybersecurity Sr. Manager

@ Eastman | Kingsport, TN, US, 37660

KDN IAM Associate Consultant

@ KPMG India | Hyderabad, Telangana, India

Learning Experience Designer in Cybersecurity (f/m/div.) (Salary: ~113.000 EUR p.a.*)

@ Bosch Group | Stuttgart, Germany

Senior Security Engineer - SIEM

@ Samsara | Remote - US