PT-2023-27752 · Macvim · Macvim
Cduplooy
·
Published
2023-09-12
·
Updated
2024-03-18
·
CVE-2023-41036
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Macvim versions prior to 178
Description
The issue is related to an insecure interprocess communication (IPC) mechanism in Macvim, a text editor for MacOS. This mechanism could lead to a privilege escalation. Distributed objects, a concept introduced by Apple, allow one program to vend an interface to another program, but the documentation does not make it clear that this service can vend the interface to any other program on the machine. The impact of exploitation is a privilege escalation to root, which is likely to affect users who are not careful about the software they download and use MacVim to edit files that require root privileges.
Recommendations
For versions prior to 178, update to version 178 or later to resolve the issue. As a temporary workaround, consider avoiding the use of MacVim to edit files that require root privileges until the update is applied.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Macvim