Description
A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve privileged file corruption.
Problem types
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
Product status
77.0 (custom)
Credits
Oscar Uribe
References
fluidattacks.com/es/advisories/soad
fluidattacks.com/es/advisories/soad
xvpn.io/...tatement-local-privilege-escalation-vulnerability
xvpn.io/download/vpn-mac
xvpn.io/