PT-2026-28337 · Unknown · Vienna Assistant
Florian Haselsteiner
·
Published
2026-03-26
·
Updated
2026-03-27
·
CVE-2026-24068
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vienna Assistant (affected versions not specified)
Description
The Vienna Assistant privileged helper utilizes NSXPC for Inter-Process Communication (IPC). The implementation of the
shouldAcceptNewConnection function, used by the NSXPC framework to validate client connections to the XPC listener, does not perform any client validation. This allows any process to connect to the service using the configured protocol and call all functions defined in the HelperToolProtocol. Specifically, the functions writeReceiptFile and runUninstaller within the HelperToolProtocol lack validation, enabling an attacker to write files to any location with arbitrary data and execute any file with any arguments. The absence of XPC client validation allows any process to invoke these functions, leading to privilege escalation. The vendor was unresponsive and did not provide a patch.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vienna Assistant