vendor:
Arq
by:
m4rkw
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Arq
Affected Version From: Arq <= 5.9.7
Affected Version To: Arq 5.9.7
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac
2020
Arq <= 5.9.7 local root privilege escalation exploit
This exploit is related to the suid-root restorer binaries in Arq for Mac. After reversing the inter-app protocol, it was discovered that the path to the restorer binary was specified as part of the data packet sent by the UI. After receiving this, the restorer binaries then set +s and root ownership on this path, allowing an attacker to specify an arbitrary path which will receive +s and root ownership.
Mitigation:
Upgrade to Arq 5.10 or later.