CVE-2024-14032 is a privilege escalation vulnerability affecting Twitch Studio version 0.114.8 and earlier, caused by an unprotected XPC service in the application's privileged helper tool. The flaw allows local attackers to execute arbitrary code as root by exploiting the installFromPath:toPath:withReply: method to overwrite system files and privileged binaries, resulting in complete system compromise. With a CVSS score of 7.8 (HIGH), the vulnerability requires local access with low privileges and has high impact across confidentiality, integrity, and availability. The attack presents a low exploit barrier given the straightforward nature of invoking the vulnerable XPC method. Exploitation activity appears minimal at present, as the vulnerability is not tracked on the Known Exploited Vulnerabilities catalog and shows no evidence of active in-the-wild attacks, though the risk profile remains elevated due to the severity of potential impact and the simplicity of exploitation. It should be noted that Twitch Studio was discontinued in May 2024, reducing the practical attack surface.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.114.8CPE matchmatch criteria | cpe:2.3:a:twitch:twitch_studio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.