ZeroHour

CVE-2023-41902

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
Description

An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files.

Vendors
corecode
Products
macupdater
Weakness
CWE-434
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.