Metrics
Affected Vendors & Products
Mon, 24 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-267 | |
| Metrics |
cvssV3_1
|
Tue, 18 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-798 | |
| Metrics |
cvssV3_1
|
Wed, 29 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-798 | |
| Metrics |
cvssV3_1
|
Tue, 28 Jan 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handling privileged operations within the macOS DTEX Event Forwarder agent, fails to implement critical client validation during XPC interprocess communication (IPC). Specifically, the service does not verify the code requirements, entitlements, security flags, or version of any client attempting to establish a connection. This lack of proper logic validation allows malicious actors to exploit the service's methods via unauthorized client connections, and escalate privileges to root by abusing the DTConnectionHelperProtocol protocol's submitQuery method over an unauthorized XPC connection. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-01-28T00:00:00.000Z
Updated: 2025-03-24T16:20:21.772Z
Reserved: 2024-12-14T00:00:00.000Z
Link: CVE-2024-55968
Updated: 2025-01-29T14:39:18.242Z
Status : Awaiting Analysis
Published: 2025-01-28T22:15:15.860
Modified: 2025-03-24T17:15:19.730
Link: CVE-2024-55968
No data.