Impact
Improper validation of XPC caller certificates in the PrivilegedHelperTool service of the Cato Networks SDP Client allows a local authenticated attacker to bypass certificate chain checks and obtain root privileges. The vulnerability also includes a time‑of‑check time‑of‑use race condition that can be exploited by swapping a symbolic link during installation, resulting in the helper tool running with elevated rights. The affected code therefore permits arbitrary privileged execution locally through either certificate manipulation (CWE‑295) or a symlink race (CWE‑367).
Affected Systems
Cato Networks SDP Client versions earlier than 5.13.1 on macOS are affected; no other vendors or operating systems are mentioned.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate risk, while < 1 % shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local authentication or control during the installation process, and once triggered, the attacker gains full root access to on the description, it is inferred that the attack cannot be performed remotely and is limited to users with local privileges or those able to influence the installation sequence.
OpenCVE Enrichment