CVE-2024-46060

high

Description

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.

References

https://www.anaconda.com/docs/getting-started/anaconda/release/2024.x#anaconda-2024-06-1

https://m8sec.dev/blog/privilege-escalation-macos-pkg-installers/

Details

Source: Mitre, NVD

Published: 2025-12-17

Updated: 2025-12-18

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00019