PT-2023-28087 · Unknown · Direct Desktop App
Koh M. Nakagawa
·
Published
2023-09-08
·
Updated
2023-09-14
·
CVE-2023-41775
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
direct Desktop App for macOS versions 2.6.0 and earlier
Description
The issue allows a local attacker to bypass access restrictions and use the camera, microphone, etc. of the device where the product is installed without the user's consent. This is due to an improper access control vulnerability.
Recommendations
For versions 2.6.0 and earlier, update to a version later than 2.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the device's camera and microphone to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Direct Desktop App