CVE-2024-4395

T

he XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.

Configurations

No configuration.

History

21 Nov 2024, 09:42

Type Values Removed Values Added
References () https://github.com/Jamf-Concepts/jamf-compliance-editor/raw/v1.3.1/Jamf%20Compliance%20Editor%20-%20User%20Guide.pdf - () https://github.com/Jamf-Concepts/jamf-compliance-editor/raw/v1.3.1/Jamf%20Compliance%20Editor%20-%20User%20Guide.pdf -
References () https://github.com/Jamf-Concepts/jamf-compliance-editor/releases/download/v1.3.1/JamfComplianceEditor.v1.3.1.pkg - () https://github.com/Jamf-Concepts/jamf-compliance-editor/releases/download/v1.3.1/JamfComplianceEditor.v1.3.1.pkg -
References () https://khronokernel.com/macos/2024/05/01/CVE-2024-4395.html - () https://khronokernel.com/macos/2024/05/01/CVE-2024-4395.html -
References () https://trusted.jamf.com/docs/establishing-compliance-baselines#support - () https://trusted.jamf.com/docs/establishing-compliance-baselines#support -

03 Jul 2024, 02:07

Type Values Removed Values Added
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) El servicio XPC dentro de la funcionalidad de auditoría de Jamf Compliance Editor anterior a la versión 1.3.1 en macOS puede provocar una escalada de privilegios locales.

27 Jun 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 22:15

Updated : 2024-11-21 09:42


NVD link : CVE-2024-4395

Mitre link : CVE-2024-4395

CVE.ORG link : CVE-2024-4395


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management