We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2098

Dylib Hijacking in Fast CAD Reader



Description

Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation. This issue affects Fast CAD Reader in possibly all versions since the vendor has not responded to our messages. The tested version was 4.1.5

Reserved 2025-03-07 | Published 2025-03-26 | Updated 2025-03-26 | Assigner CERT-PL


HIGH: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-266 Incorrect Privilege Assignment

Product status

Default status
unknown

Any version
affected

Credits

Karol Mazurek with AFINE finder

References

cert.pl/en/posts/2025/03/CVE-2025-2098/ third-party-advisory

apps.apple.com/pl/app/fast-cad-reader/id1484905765 product

cve.org (CVE-2025-2098)

nvd.nist.gov (CVE-2025-2098)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2098

Support options

Helpdesk Chat, Email, Knowledgebase