The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation.
2020-12-16T15:15:12.807
2024-11-21T05:32:09.273
Modified
CVSSv3.1: 3.6 (LOW)
AV:L/AC:M/Au:N/C:N/I:P/A:P
3.4
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | carbon_black_cloud | < 3.5.1 | Yes |
Operating System | apple | macos | - | No |