vendor:
Disconnect.me
by:
Kristian Erik Hermansen
9,8
CVSS
HIGH
Local Privilege Escalation
269
CWE
Product Name: Disconnect.me
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: None
CPE: a:disconnect:disconnect_me
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac OS X
2020
Disconnect.me Mac OS X Client LPE to Root Vulnerability (0day)
The Mac OS X client of Disconnect.me has a local privilege escalation vulnerability (0day). The original download of version 2.0 or below is available at https://disconnect.me/premium/mac, and an archived download is available at http://d-h.st/LKqG. The Disconnect+Desktop.pkg has a sha256 of bc94c94c88eb5c138396519ff994ae8efe85899475f44e54f71a6ebc047ce4e7. The proof of concept involves creating a script in the /tmp directory, setting the PATH to /tmp, and running the “/Library/Application Support/disconnect/stopvpn” command, which will then run the script as root.
Mitigation:
Users should update to the latest version of Disconnect.me, which is not vulnerable to this exploit.