PT-2020-14381 · Binarynights · Forklift
Birk Kauer
·
Published
2020-11-14
·
Updated
2021-07-21
·
CVE-2020-15349
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BinaryNights ForkLift versions 3.x before 3.4
Description
The issue is related to a local privilege escalation due to the implementation of an XPC interface in the privileged helper tool. This interface allows any process to perform file operations such as copy, move, delete as root, and also change permissions.
Recommendations
For BinaryNights ForkLift versions 3.x before 3.4, update to version 3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the XPC interface implemented by the privileged helper tool to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forklift