CVE-2021-41388: High severity netskope vulnerability
Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on new connections before accepting the connection. Thus any low privileged user can connect and call external methods defined in XPC service as root, elevating their privilege to the highest level.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-41388?
CVE-2021-41388 is a local privilege escalation vulnerability in Netskope client prior to version 89.x on macOS.
How does CVE-2021-41388 affect macOS?
CVE-2021-41388 allows any low privileged user on macOS to connect and call external methods in the nsAuxiliarySvc process of Netskope client prior to version 89.x.
What is the severity of CVE-2021-41388?
CVE-2021-41388 has a severity rating of 7.8 (high).
How can I fix CVE-2021-41388?
To fix CVE-2021-41388, update Netskope client to version 89.x or later.
Where can I find more information about CVE-2021-41388?
You can find more information about CVE-2021-41388 in the Netskope Security Advisory NSKPSA-2021-002: [https://www.netskope.com/company/security-compliance-and-assurance/netskope-security-advisory-nskpsa-2021-002](https://www.netskope.com/company/security-compliance-and-assurance/netskope-security-advisory-nskpsa-2021-002).