CVE-2023-41775

Improper access control vulnerability in 'direct' Desktop App for macOS ver 2.6.0 and earlier allows a local attacker to bypass access restriction and to use camrea, microphone, etc. of the device where the product is installed without the user's consent.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:l-is-b:direct:*:*:*:*:desktop:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

14 Sep 2023, 16:48

Type Values Removed Values Added
CPE cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:l-is-b:direct:*:*:*:*:desktop:*:*:*
CWE NVD-CWE-Other
References (MISC) https://status.direct4b.com/2023/08/31/2023083101/ - (MISC) https://status.direct4b.com/2023/08/31/2023083101/ - Vendor Advisory
References (MISC) https://jvn.jp/en/jp/JVN42691027/ - (MISC) https://jvn.jp/en/jp/JVN42691027/ - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time L-is-b
L-is-b direct
Apple
Apple macos

08 Sep 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-08 08:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-41775

Mitre link : CVE-2023-41775

CVE.ORG link : CVE-2023-41775


JSON object : View

Products Affected

apple

  • macos

l-is-b

  • direct