CVE-2024-8272
macOS Universal Audio (UAConnect) <= 2.7.0 - Local Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The com.uaudio.bsd.helperĀ service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.
The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to establish a connection. This lack of proper validation allows unauthorized clients to exploit the service's methods and escalate privileges to root.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-08-28 CVE Reserved
- 2024-11-25 CVE Published
- 2024-11-25 CVE Updated
- 2024-11-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Universal Audio Search vendor "Universal Audio" | UAConnect Search vendor "Universal Audio" for product "UAConnect" | <= 2.7.0 Search vendor "Universal Audio" for product "UAConnect" and version " <= 2.7.0" | en |
Affected
|