Local Privilege Escalation in Nimble Commander <= v1.6.0, Build 4087
Vulnerability Description
Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute system-level commands as the root user, such as changing permissions and ownership, obtaining a handle (file descriptor) of an arbitrary file, and terminating processes, among other operations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-7062
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Carlos Garrido of Pentraze Cybersecurity
Affected Vendor
Nimble Commander
View all reports →