Description
The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation.
Problem types
CWE-306 Missing authentication for critical function
Product status
2.12.0.3157
Credits
Florian Haselsteiner, SEC Consult Vulnerability Lab
References
r.sec-consult.com/arturia