PT-2020-17759 · Apple · Macos Catalina

Hackeron2Wheels

+3

·

Published

2020-02-27

·

Updated

2021-07-21

·

CVE-2020-3866

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions macOS Catalina versions prior to 10.15.3
Description The issue allows an attacker to bypass Gatekeeper by searching for and opening a file from an attacker-controlled NFS mount. This was addressed with additional checks by Gatekeeper on files mounted through a network share.
Recommendations For macOS Catalina versions prior to 10.15.3, update to macOS Catalina 10.15.3 to resolve the issue. As a temporary workaround, consider restricting access to NFS mounts from untrusted sources to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-3866

Affected Products

Macos Catalina