An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies to macOS before 10.15.5, or Security Update 2020-003 on Mojave and High Sierra, Later versions of macOS are not vulnerable.)
References
Link | Resource |
---|---|
https://www.beyondtrust.com/docs/release-notes/privilege-management/index.htm | Release Notes |
https://www.beyondtrust.com/trust-center/security-advisories/bt22-06 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
14 Dec 2023, 16:48
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-11 23:15
Updated : 2024-02-28 20:54
NVD link : CVE-2021-3187
Mitre link : CVE-2021-3187
CVE.ORG link : CVE-2021-3187
JSON object : View
Products Affected
apple
- mac_os_x
beyondtrust
- privilege_management_for_mac
CWE