PT-2025-48967 · Unknown · Aquarius Helpertool
Simon Bertrand
·
Published
2025-12-03
·
Updated
2025-12-03
·
CVE-2025-65842
CVSS v3.1
5.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Aquarius HelperTool version 1.0.003
Description
The Aquarius HelperTool on macOS contains flaws that allow local privilege escalation. The service accepts XPC connections from any local process without validating the client’s identity. Its authorization logic incorrectly calls
AuthorizationCopyRights() with a NULL reference, causing all authorization checks to succeed. The executeCommand:authorization:withReply: method then interpolates attacker-controlled input into NSTask and executes it with root privileges. A local attacker can exploit these weaknesses to run arbitrary commands as root, create persistent backdoors, or obtain a fully interactive root shell.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
LPE
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aquarius Helpertool