CVE-2024-7062
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jul 26, 2024
CWE ID 863
Summary
CVE-2024-7062 is a privilege escalation vulnerability affecting Nimble Commander. The issue lies in the server component (info.filesmanager.Files.PrivilegedIOHelperV2) that fails to properly validate client authorization before executing certain operations. This flaw enables unauthorized users to execute system-level commands with root privileges, potentially leading to significant security risks. These risks encompass altering file permissions and ownership, accessing arbitrary files, and terminating processes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.