Description
The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49537 | The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root. |
References
| Link | Providers |
|---|---|
| https://pentraze.com/vulnerability-reports |
|
History
Mon, 25 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Universal Audio
Universal Audio uaconnect |
|
| CPEs | cpe:2.3:a:universal_audio:uaconnect:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Universal Audio
Universal Audio uaconnect |
|
| Metrics |
ssvc
|
Mon, 25 Nov 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root. | |
| Title | macOS Universal Audio (UAConnect) <= 2.7.0 - Local Privilege Escalation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Pentraze
Published:
Updated: 2024-11-25T18:42:00.202Z
Reserved: 2024-08-28T17:48:16.683Z
Link: CVE-2024-8272
Updated: 2024-11-25T18:41:55.457Z
Status : Received
Published: 2024-11-25T18:15:14.673
Modified: 2024-11-25T18:15:14.673
Link: CVE-2024-8272
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD