CVE-2019-5011
Summary
| CVE | CVE-2019-5011 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-21 16:01:00 UTC |
| Updated | 2022-06-13 18:59:00 UTC |
| Description | An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improper updating. The application failed to remove the vulnerable components upon upgrading to the latest version, leaving the user open to attack. A user with local access can use this vulnerability to modify the file system as root. An attacker would need local access to the machine for a successful exploit. |
Risk And Classification
Problem Types: CWE-459
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Macpaw | Cleanmymac X | 4.20 | All | All | All |
| Application | Macpaw | Cleanmymac X | 4.20 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TALOS-2019-0759 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence | MISC | talosintelligence.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.