Impact
Exam4 contains a local privilege escalation vulnerability in its com.extegrity.LogTool privileged helper. The helper communicates with the main application via XPC and runs a syslog command in the method copyConsoleIntoFileFromStartDate: without sanitizing attacker‑controlled parameters, allowing command injection. An attacker who can execute the helper locally can run arbitrary commands with root privileges through LaunchSynchronous, compromising system confidentiality, integrity, and availability.
Affected Systems
The affected product is Extegrity Exam4. No specific version information is provided in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a high severity, while the EPSS score is not available and it is not listed in the CISA KEV catalog. It requires local access and is enabled by the privileged LogTool helper, so a local attacker who can trigger the XPC call can inject commands via syslog. The execution path requires the attacker to invoke the helper as root, which is granted by the helper’s launchd configuration, making exploitation straightforward for anyone with local account access.
OpenCVE Enrichment