Description
Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute system-level commands as the root user, such as changing permissions and ownership, obtaining a handle (file descriptor) of an arbitrary file, and terminating processes, among other operations.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48059 | Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute system-level commands as the root user, such as changing permissions and ownership, obtaining a handle (file descriptor) of an arbitrary file, and terminating processes, among other operations. |
References
| Link | Providers |
|---|---|
| https://pentraze.com/vulnerability-reports/CVE-2024-7062/ |
|
History
Tue, 27 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Mikekazakov Mikekazakov nimble Commander |
|
| CPEs | cpe:2.3:a:mikekazakov:nimble_commander:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple macos Mikekazakov Mikekazakov nimble Commander |
Status: PUBLISHED
Assigner: Pentraze
Published:
Updated: 2024-08-01T21:52:30.436Z
Reserved: 2024-07-23T22:18:58.485Z
Link: CVE-2024-7062
Updated: 2024-08-01T21:52:30.436Z
Status : Modified
Published: 2024-07-26T12:15:03.873
Modified: 2024-11-21T09:50:49.053
Link: CVE-2024-7062
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD