PT-2025-12971 · Unknown · Fast Cad Reader
Published
2025-03-26
·
Updated
2025-04-09
·
CVE-2025-2098
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Fast CAD Reader versions prior to a fixed version (no specific fixed version mentioned, affected versions not specified)
Description
The Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx), which is inconsistent with standard macOS security practices. This inconsistency allows for Dylib Hijacking, enabling guest accounts, other users, and applications to exploit this issue for privilege escalation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Privilege Assignment
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fast Cad Reader