CVE-2024-7062 - Nimble Commander Root Privilege Escalation

CVE ID : CVE-2024-7062 Published : July 26, 2024, 12:15 p.m. | 44 minutes ago Description : Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute system-level commands as the root user, such as changing permissions and ownership, obtaining a handle (file descriptor) of an arbitrary file, and terminating processes, among other operations. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Jul 26, 2024 - 15:00
 0  1
CVE-2024-7062 - Nimble Commander Root Privilege Escalation
CVE ID : CVE-2024-7062
Published : July 26, 2024, 12:15 p.m. | 44 minutes ago
Description : Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute system-level commands as the root user, such as changing permissions and ownership, obtaining a handle (file descriptor) of an arbitrary file, and terminating processes, among other operations.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...