CVE-2023-41138
09.11.2023, 15:15
The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.Enginsight
Vendor | Product | Version |
---|---|---|
appsanywhere | appsanywhere_client | 1.4.0 |
appsanywhere | appsanywhere_client | 1.4.1 |
appsanywhere | appsanywhere_client | 1.5.1 |
appsanywhere | appsanywhere_client | 1.5.2 |
appsanywhere | appsanywhere_client | 1.6.0 |
appsanywhere | appsanywhere_client | 2.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-226 - Sensitive Information in Resource Not Removed Before ReuseThe product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.