CyberRota Analysis
AI-GeneratedA local privilege escalation vulnerability exists in the com.extegrity.LogTool privileged helper of Exam4, allowing attackers to exploit the copyConsoleIntoFileFromStartDate: method to inject arbitrary commands due to inadequate input sanitization. This flaw enables local attackers to execute commands with root privileges, posing a significant security risk. Organizations using Exam4 should prioritize patching this vulnerability to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to execute arbitrary commands with root privileges through LaunchSynchronous.