Impact
A local privilege escalation flaw exists in the com.deskin.service.installer XPC service shipped with Deskin 3.3.4.3. Because the service runs as root and accepts connections from any local user without authentication, an unprivileged user can connect to the service and invoke a method that installs arbitrary software. The installer runs with root privileges, allowing the attacker to execute any code and obtain full system control. This exploit is a classic example of a missing authentication check, indexed as CWE-306.
Affected Systems
The vulnerability affects the DeskIn application by Zuler Technology, specifically version 3.3.4.3 of Deskin. Any macOS machine running this build is susceptible; other versions are not listed as impacted.
Risk and Exploitability
The flaw carries a high CVSS score of 8.5. No EPSS score is available, but the absence of a KEV listing does not reduce risk. Attackers only need local access, which is common on shared systems or for roaming users, and the exploitation path requires no special network privileges. Because the service is root‑owned and lacks authentication, the attack is straightforward once the user can trigger the installer method, yielding complete root compromise. This high severity and local availability make the vulnerability a serious risk in environments where desk/laptop access is shared or where untrusted users reside.
OpenCVE Enrichment