CVE-2022-27904

Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process.
References
Link Resource
https://automox.com Vendor Advisory
https://www.automox.com/security/security-bulletin Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:automox:automox:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

21 Jul 2022, 17:15

Type Values Removed Values Added
Summary The Automox Agent installation package before 37 on macOS allows an unprivileged user to obtain root access because of incorrect access control on a file used within the PostInstall script. Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process.

14 Jul 2022, 16:22

Type Values Removed Values Added
CPE cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:automox:automox:*:*:*:*:*:*:*:*
First Time Automox automox
Apple
Automox
Apple macos
CVSS v2 : unknown
v3 : unknown
v2 : 6.9
v3 : 7.0
CWE CWE-367
References (MISC) https://automox.com - (MISC) https://automox.com - Vendor Advisory
References (MISC) https://www.automox.com/security/security-bulletin - (MISC) https://www.automox.com/security/security-bulletin - Vendor Advisory

01 Jul 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-01 00:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-27904

Mitre link : CVE-2022-27904

CVE.ORG link : CVE-2022-27904


JSON object : View

Products Affected

apple

  • macos

automox

  • automox
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition