vendor:
HospitalRun
by:
Jean Pereira
N/A
CVSS
HIGH
Local Root Exploit
CWE
Product Name: HospitalRun
Affected Version From: 1.0.0-beta
Affected Version To: 1.0.0-beta
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: macOS Ventura 13.2.1 (22D68)
2023
HospitalRun 1.0.0-beta – Local Root Exploit for macOS
This exploit allows an attacker to gain privileged rights (e.g. root) on a macOS system running HospitalRun version 1.0.0-beta. By running a local TCP listener and executing the exploit, the attacker can execute commands and escalate their privileges.
Mitigation:
To patch this vulnerability, remove write permissions from the electron.asar file.