com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell metacharacters in usingCAPath.
References
Link | Resource |
---|---|
https://support.perimeter81.com/docs/macos-agent-release-notes | Release Notes |
https://www.kb.cert.org/vuls/id/653767 | Third Party Advisory US Government Resource |
https://www.ns-echo.com/posts/cve_2023_33298.html | Exploit Technical Description Third Party Advisory |
https://support.perimeter81.com/docs/macos-agent-release-notes | Release Notes |
https://www.kb.cert.org/vuls/id/653767 | Third Party Advisory US Government Resource |
https://www.ns-echo.com/posts/cve_2023_33298.html | Exploit Technical Description Third Party Advisory |
Configurations
History
27 Nov 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 |
21 Nov 2024, 08:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.perimeter81.com/docs/macos-agent-release-notes - Release Notes | |
References | () https://www.kb.cert.org/vuls/id/653767 - Third Party Advisory, US Government Resource | |
References | () https://www.ns-echo.com/posts/cve_2023_33298.html - Exploit, Technical Description, Third Party Advisory |
02 Aug 2023, 15:40
Type | Values Removed | Values Added |
---|---|---|
References | (CERT-VN) https://www.kb.cert.org/vuls/id/653767 - Third Party Advisory, US Government Resource |
20 Jul 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Jul 2023, 22:56
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CPE | cpe:2.3:a:perimeter81:xpc_helpertool:10.0.0.19:*:*:*:*:macos:*:* | |
CWE | NVD-CWE-noinfo | |
References | (MISC) https://support.perimeter81.com/docs/macos-agent-release-notes - Release Notes | |
References | (MISC) https://www.ns-echo.com/posts/cve_2023_33298.html - Exploit, Technical Description, Third Party Advisory |
03 Jul 2023, 01:10
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-30 22:15
Updated : 2024-11-27 17:15
NVD link : CVE-2023-33298
Mitre link : CVE-2023-33298
CVE.ORG link : CVE-2023-33298
JSON object : View
Products Affected
perimeter81
- xpc_helpertool
CWE
NVD-CWE-noinfo
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')