CVE-2021-20172 is a local privilege escalation vulnerability affecting all known versions of the Netgear Genie Installer for macOS. The installer insecurely handles certain files, allowing a local attacker to overwrite them and gain root privileges. This vulnerability has a CVSS score of 7.8 (High) due to its low attack complexity and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netgear:genie_installer:-:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Netgear Genie MacOS Installer Privilege Escalation
Dec 30, 2021Netgear Genie MacOS Installer Privilege Escalation
Dec 30, 2021Netgear Genie MacOS Installer Privilege Escalation
Dec 30, 2021