An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handling privileged operations within the macOS DTEX Event Forwarder agent, fails to implement critical client validation during XPC interprocess communication (IPC). Specifically, the service does not verify the code requirements, entitlements, security flags, or version of any client attempting to establish a connection. This lack of proper logic validation allows malicious actors to exploit the service's methods via unauthorized client connections, and escalate privileges to root by abusing the DTConnectionHelperProtocol protocol's submitQuery method over an unauthorized XPC connection.
References
Configurations
No configuration.
History
24 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-267 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
18 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | ||
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
29 Jan 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | CWE-798 |
28 Jan 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-28 22:15
Updated : 2025-03-24 17:15
NVD link : CVE-2024-55968
Mitre link : CVE-2024-55968
CVE.ORG link : CVE-2024-55968
JSON object : View
Products Affected
No product.
CWE
CWE-267
Privilege Defined With Unsafe Actions