ZDI-25-252: (0Day) Cato Networks Cato Client for macOS Helper Service Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Cato Networks Cato Client for macOS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-252?
The severity of ZDI-25-252 is classified as critical due to the potential for privilege escalation.
How do I fix ZDI-25-252?
To fix ZDI-25-252, update the Cato Client for macOS to the latest version provided by Cato Networks.
Who is affected by ZDI-25-252?
ZDI-25-252 affects users of Cato Networks Cato Client for macOS who have not applied the necessary security updates.
What type of attack does ZDI-25-252 facilitate?
ZDI-25-252 facilitates local privilege escalation attacks by allowing attackers to execute code with elevated permissions.
Is authentication required to exploit ZDI-25-252?
Yes, an attacker must first gain access to execute low-privileged code on the system to exploit ZDI-25-252.