CVE-2022-26704

high

Description

A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.4. An app may be able to gain elevated privileges.

References

https://support.apple.com/en-us/HT213257

https://support.apple.com/kb/HT213343

http://seclists.org/fulldisclosure/2022/Jul/14

https://support.apple.com/kb/HT213344

http://seclists.org/fulldisclosure/2022/Jul/13

https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0032/MNDT-2022-0032.md

Details

Source: MITRE

Published: 2022-05-26

Updated: 2022-11-10

Type: CWE-59

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH