The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Mon, 25 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Universal Audio
Universal Audio uaconnect
CPEs cpe:2.3:a:universal_audio:uaconnect:*:*:*:*:*:*:*:*
Vendors & Products Universal Audio
Universal Audio uaconnect
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 Nov 2024 18:00:00 +0000

Type Values Removed Values Added
Description The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.
Title macOS Universal Audio (UAConnect) <= 2.7.0 - Local Privilege Escalation
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Pentraze

Published:

Updated: 2024-11-25T18:42:00.202Z

Reserved: 2024-08-28T17:48:16.683Z

Link: CVE-2024-8272

cve-icon Vulnrichment

Updated: 2024-11-25T18:41:55.457Z

cve-icon NVD

Status : Received

Published: 2024-11-25T18:15:14.673

Modified: 2024-11-25T18:15:14.673

Link: CVE-2024-8272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.