7.5

CVE-2023-41138

The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppsanywhereAppsanywhere Client Version1.4.0 SwPlatformmacos
AppsanywhereAppsanywhere Client Version1.4.1 SwPlatformmacos
AppsanywhereAppsanywhere Client Version1.5.1 SwPlatformmacos
AppsanywhereAppsanywhere Client Version1.5.2 SwPlatformmacos
AppsanywhereAppsanywhere Client Version1.6.0 SwPlatformmacos
AppsanywhereAppsanywhere Client Version2.0.0 SwPlatformmacos
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.036
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
info@appcheck-ng.com 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-226 Sensitive Information in Resource Not Removed Before Reuse

The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.

CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.