vendor:
Viscosity
by:
zx2c4
7,2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Viscosity
Affected Version From: Viscosity 1.0
Affected Version To: Viscosity 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sparklabs:viscosity
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OS X
2011
Viscatory
Viscatory is a local privilege escalation vulnerability in Viscosity, an OS X VPN client. The SUID helper will execute site.py in its enclosing folder, allowing a simple symlink to gain root access.
Mitigation:
Ensure that the SUID helper is not vulnerable to symlink attacks.