Impact
Improper validation of the XPC caller certificate in the PrivilegedHelperTool service of the Cato Networks SDP Client permits a local authenticated attacker to bypass the certificate chain checks and gain root privileges. The vulnerability also includes a time‑of‑check time‑of‑use race condition that can be exploited by swapping a symbolic link during installation, allowing the helper tool to run with elevated rights. The flaw therefore permits arbitrary privileged execution locally through either certificate manipulation (CWE‑295) or a symlink race (CWE‑367).
Affected Systems
Cato Networks SDP Client on macOS versions earlier than 5.13.1 are affected; no other vendors or operating systems are mentioned.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate risk, while < 1 % shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local authentication or control during the installation process, and the attack cannot be performed remotely; it is limited to users who can execute local code or influence the installation sequence.
OpenCVE Enrichment