Impact
A time‑of‑check to time‑of‑use (TOCTOU) race condition exists in Microsoft Defender for Endpoint for Mac, allowing an attacker who already has local authorization to elevate privileges. The flaw arises when a check of a file or resource is performed before the resource is used, and the race can be exploited to trick the program into performing operations with higher privileges. The impact is the gain of elevated system rights, potentially compromising the entire Mac system used by the attacker. The weakness is a classic race‑condition flaw (CWE‑367).
Affected Systems
All macOS installations running Microsoft Defender for Endpoint that have not yet applied the issued update are potentially affected. The vulnerability is linked to the Microsoft Defender for Endpoint for Mac product and any versions installed prior to the vendor’s fix.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the medium severity range. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild at this time, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is local: an attacker must have some level of permission on the device and can manipulate the OS or Defender processes to create the TOCTOU window. Given the low EPSS and lack of active exploitation reports, the risk remains moderate, but the impact of privilege escalation warrants prompt attention.
OpenCVE Enrichment