Impact
A time‑of‑check time‑of‑use (TOCTOU) race condition exists in Microsoft Defender for Endpoint for Mac that permits an attacker with local authorization to elevate privileges. The flaw arises when the software checks a file or resource state and the state changes before the operation completes, enabling the attacker to manipulate the operation and gain elevated rights. The weakness is classified as CWE‑367, which reflects improper handling of resource state during concurrent operations.
Affected Systems
Microsoft Defender for Endpoint for Mac is the affected product. No specific version range is provided in the public data, indicating all installed instances may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.0 indicates a medium severity, and the EPSS score of less than 1% suggests that, while exploitation is possible, it is currently unlikely to occur at scale. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker with user-level access on the machine would need to trigger the race condition, which may maliciously timed actions. Due to the medium severity score, organizations should treat this as a priority risk when Microsoft releases a fix.
OpenCVE Enrichment