目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-45599— Cursor 安全漏洞

一分钟漏洞结论

影响对象
getcursor cursor
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Cursor是Cursor开源的一个 AI 代码编辑器。 Cursor 0.41.0之前版本存在安全漏洞,该漏洞源于如果macOS上的用户已授予Cursor对摄像头或麦克风的访问权限,则在机器上运行的任何程序都可以通过使用环境变量注入来访问摄像头或麦克风,而无需明确授予访问权限。

CVSS 3.8 · Low EPSS 0.18% · P7
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-45599 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
TCC Bypass in Cursor's macOS Application
来源: CVE Program / CVE List V5
Vulnerability Description
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or the microphone without explicitly being granted access, through a DyLib Injection using DYLD_INSERT_LIBRARIES environment variable. The usage of `com.apple.security.cs.allow-dyld-environment-variables` and `com.apple.security.cs.disable-library-validation` allows an external dynamic library to be injected into the application using DYLD_INSERT_LIBRARIES environment variable. Moreover, the entitlement `com.apple.security.device.camera` allows the application to use the host camera and `com.apple.security.device.audio-input` allows the application to use the microphone. This means that untrusted code that is executed on the user's machine can access the camera or the microphone, if the user has already given permission for Cursor to do so. In version 0.41.0, the entitlements have been split by process: the main process gets the camera and microphone entitlements, but not the DyLib entitlements, whereas the extension host process gets the DyLib entitlements but not the camera or microphone entitlements. As a workaround, do not explicitly give Cursor the permission to access the camera or microphone if untrusted users can run arbitrary commands on the affected machine.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
不安全的继承权限
来源: CVE Program / CVE List V5
Vulnerability Title
Cursor 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Cursor是Cursor开源的一个 AI 代码编辑器。 Cursor 0.41.0之前版本存在安全漏洞,该漏洞源于如果macOS上的用户已授予Cursor对摄像头或麦克风的访问权限,则在机器上运行的任何程序都可以通过使用环境变量注入来访问摄像头或麦克风,而无需明确授予访问权限。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
getcursor cursor < 0.41.0 -

二、漏洞 CVE-2024-45599 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-45599 的情报信息

请登录查看更多情报信息。

CVE-2024-45599 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-45599

暂无评论


发表评论