Description
The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- AppsAnywhere / AppsAnywhere Client1.4.0 – 1.4.0
- AppsAnywhere / AppsAnywhere Client1.4.1 – 1.4.1
- AppsAnywhere / AppsAnywhere Client1.5.1 – 1.5.1
- AppsAnywhere / AppsAnywhere Client1.5.2 – 1.5.2
- AppsAnywhere / AppsAnywhere Client1.6.0 – 1.6.0
- AppsAnywhere / AppsAnywhere Client2.0.0 – 2.0.0
- AppsAnywhere / AppsAnywhere Client1.6.1 – 1.6.1
- AppsAnywhere / AppsAnywhere Client2.0.1 – 2.0.1
- AppsAnywhere / AppsAnywhere Client2.2.0 – 2.2.0