Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability with its com.privat.vpn.helper privileged helper tool. This privileged helper tool implements an XPC service that allows arbitrary installed applications to connect and send messages. The XPC service extracts the path string from the corresponding XPC message. This string is supposed to point to PrivateVPN's internal openvpn binary. If a new connection has not already been established, an attacker can send the XPC service a malicious XPC message with the path string pointing at a binary that he or she controls. This results in the execution of arbitrary code as the root user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PrivateVPN for macOS 权限许可和访问控制问题漏洞
Vulnerability Description
PrivateVPN for macOS是一款基于macOS平台的VPN软件,用于匿名访问互联网。 基于macOS平台的PrivateVPN 2.0.31版本中存在提权漏洞。攻击者可通过向XPC服务发送带有路径字符串并指向受攻击者控制的库的恶意XPC消息利用该漏洞以root用户身份执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A