漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Slate Digital Connect macOS XPC PID validation privilege escalation
Vulnerability Description
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve code-signing information for the process. This PID-based client validation is subject to a time-of-check time-of-use race condition because process identifiers can be reused. A local attacker can exploit PID reuse so that validation is performed against a trusted process instead of the original connecting process. This allows unauthorized access to privileged helper functionality and may lead to local privilege escalation.
CVSS Information
N/A
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Vulnerability Title
Slate Digital Connect 安全漏洞
Vulnerability Description
Slate Digital Connect是Slate Digital公司的一款音频插件管理与授权客户端。 Slate Digital Connect 1.37.0版本存在安全漏洞,该漏洞源于基于PID的客户端验证存在检查时间与使用时间竞争条件,可能导致本地攻击者利用PID重用绕过验证,导致本地权限提升。
CVSS Information
N/A
Vulnerability Type
N/A