CVE-2024-23742# CVE-2024-23742
An issue in Loom through 0.196.1 on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
<img width="287" alt="image" src="https://github.com/V3x0r/CVE-2024-23742/assets/83291215/2f20e8b6-6351-43b6-9df4-1f2ca2024c05">
With this tool, we can check if the App is Vulnerable:
<img width="848" alt="image" src="https://github.com/V3x0r/CVE-2024-23742/assets/83291215/f52a84d7-57a2-4ed5-ac47-51adf962be49">
After validation, we can inject our code, and get a shell
<img width="842" alt="image" src="https://github.com/V3x0r/CVE-2024-23742/assets/83291215/0675b594-4f0a-4159-8895-f2a74e6764d0">
Enjoy Your Shell :)
[4.0K] /data/pocs/30134580bddd7ce9d6692414bbec30fdd04f1cce
└── [ 721] README.md
0 directories, 1 file