Lucene search

K
nvd[email protected]NVD:CVE-2023-27529
HistoryMay 25, 2023 - 10:15 a.m.

CVE-2023-27529

2023-05-2510:15:09
CWE-59
web.nvd.nist.gov
2
wacom
driver
installer
macos
vulnerability
code execution
privilege escalation

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

25.8%

Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the installer, arbitrary code may be executed with the root privilege.

Affected configurations

Nvd
Node
wacomtablet_driver_installerRange<6.4.2-1
AND
applemacosMatch-
VendorProductVersionCPE
wacomtablet_driver_installer*cpe:2.3:a:wacom:tablet_driver_installer:*:*:*:*:*:*:*:*
applemacos-cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

25.8%

Related for NVD:CVE-2023-27529