Lucene search

K
jvnJapan Vulnerability NotesJVN:90278893
HistoryMay 25, 2023 - 12:00 a.m.

JVN#90278893: Wacom Tablet Driver installer for macOS vulnerable to improper link resolution before file access

2023-05-2500:00:00
Japan Vulnerability Notes
jvn.jp
19
wacom
macos
vulnerability
link resolution
file access
cwe-59
root privilege
installer
fixed version
6.4.2-1

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

25.8%

Wacom Tablet Driver installer for macOS provided by Wacom contains an improper link resolution before file access vulnerability (CWE-59).

Impact

When a user is tricked to execute a small malicious script before executing the affected version of the installer, an arbitrary code may be executed with the root privilege.

Solution

Use the fixed version of the installer
When installing the driver, use the fixed version of the installer, 6.4.2-1 or later.

Products Affected

  • Wacom Tablet Driver installer, prior to 6.4.2-1 (for macOS)

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

25.8%

Related for JVN:90278893