6.7

CVE-2023-41138

The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Appsanywhere ≫ Appsanywhere Client Version 1.4.0 SwPlatform macos
Appsanywhere ≫ Appsanywhere Client Version 1.4.1 SwPlatform macos
Appsanywhere ≫ Appsanywhere Client Version 1.5.1 SwPlatform macos
Appsanywhere ≫ Appsanywhere Client Version 1.5.2 SwPlatform macos
Appsanywhere ≫ Appsanywhere Client Version 1.6.0 SwPlatform macos
Appsanywhere ≫ Appsanywhere Client Version 2.0.0 SwPlatform macos
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.07
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
info@appcheck-ng.com 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-226 Sensitive Information in Resource Not Removed Before Reuse

The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.

CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://docs.appsanywhere.com/appsanywhere/3.1/2023-11-security-advisory
Vendor Advisory