CVE-2024-27301 is a privilege escalation vulnerability affecting the root3 Support App, an open-source Apple device management application. The flaw lies in the installer's postinstall script, which uses zsh and loads the user's .zshenv file even when executed as root. An attacker can inject malicious code into .zshenv, leading to arbitrary code execution with root privileges during installation. Rated 7.3 HIGH (CVSSv3.1), this vulnerability has a local attack vector, low attack complexity, and requires user interaction, but can result in high impact to confidentiality, integrity, and availability. The EPSS score is very low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there any public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating a low level of public awareness. Users are advised to upgrade to version 2.5.1 Rev 2 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.1, < 2.5.1CPE matchmatch criteria | cpe:2.3:a:root3:support_app:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.