Vulnerability Description
Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Conda | Miniconda3 | < 23.11.0-1 |
| Apple | Macos | - |
Related Weaknesses (CWE)
References
- https://m8sec.dev/blog/privilege-escalation-macos-pkg-installers/ExploitThird Party Advisory
- https://www.anaconda.com/docs/getting-started/miniconda/release/23.x#miniconda-2Release Notes
FAQ
What is CVE-2024-46062?
CVE-2024-46062 is a vulnerability with a CVSS score of 7.8 (HIGH). Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created ...
How severe is CVE-2024-46062?
CVE-2024-46062 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-46062?
Check the references section above for vendor advisories and patch information. Affected products include: Conda Miniconda3, Apple Macos.