An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies to macOS before 10.15.5, or Security Update 2020-003 on Mojave and High Sierra, Later versions of macOS are not vulnerable.)
References
| Link | Resource |
|---|---|
| https://www.beyondtrust.com/docs/release-notes/privilege-management/index.htm | Release Notes |
| https://www.beyondtrust.com/trust-center/security-advisories/bt22-06 | Vendor Advisory |
| https://www.beyondtrust.com/docs/release-notes/privilege-management/index.htm | Release Notes |
| https://www.beyondtrust.com/trust-center/security-advisories/bt22-06 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
27 May 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-276 |
21 Nov 2024, 06:21
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.beyondtrust.com/docs/release-notes/privilege-management/index.htm - Release Notes | |
| References | () https://www.beyondtrust.com/trust-center/security-advisories/bt22-06 - Vendor Advisory |
14 Dec 2023, 16:48
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| References | () https://www.beyondtrust.com/docs/release-notes/privilege-management/index.htm - Release Notes | |
| References | () https://www.beyondtrust.com/trust-center/security-advisories/bt22-06 - Vendor Advisory | |
| CPE | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2020-002:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-005:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-002:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-006:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-002:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-001:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-004:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-005:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-001:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-003:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2018-003:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-006:*:*:*:*:*:* cpe:2.3:a:beyondtrust:privilege_management_for_mac:*:*:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-007:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2018-002:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-004:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-002:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-007:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2020-001:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-001:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:10.13.6:-:*:*:*:*:*:* |
11 Dec 2023, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-12-11 23:15
Updated : 2025-05-27 15:15
NVD link : CVE-2021-3187
Mitre link : CVE-2021-3187
CVE.ORG link : CVE-2021-3187
JSON object : View
Products Affected
apple
- mac_os_x
beyondtrust
- privilege_management_for_mac
CWE
