6.4
CVE-2026-12374
- EPSS 0.06%
- Veröffentlicht 01.07.2026 14:07:28
- Zuletzt bearbeitet 02.07.2026 17:44:12
- CVE-Watchlists
- Unerledigt
Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a symlink swap during package installation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCato Networks
≫
Produkt
SDP Client
Default Statusunaffected
Version
5.12.0
Version <
5.13.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 2505284f-8ffb-486c-bf60-e19c1097a90b | 6.4 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://support.catonetworks.com/hc/en-us/articles/37284626576413-Security-Vulnerability-CVE-2026-12374-that-Impacts-macOS-Client-Versions-Lower-than-5-13-1