Exam4 存在一个本地提权漏洞,位于通过 XPC 与应用通信的特权辅助程序 com.extegrity.LogTool 中。该方法 使用攻击者可控的参数执行 syslog 命令,且未进行适当的输入净化,从而导致命令注入漏洞。成功利用该漏洞后,本地攻击者可通过 LaunchSynchronous 机制以 root 权限执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet