PT-2023-28087 · Unknown · Direct Desktop App

Koh M. Nakagawa

·

Published

2023-09-08

·

Updated

2023-09-14

·

CVE-2023-41775

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions direct Desktop App for macOS versions 2.6.0 and earlier
Description The issue allows a local attacker to bypass access restrictions and use the camera, microphone, etc. of the device where the product is installed without the user's consent. This is due to an improper access control vulnerability.
Recommendations For versions 2.6.0 and earlier, update to a version later than 2.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the device's camera and microphone to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2023-41775

Affected Products

Direct Desktop App