Back to Database
Status published
High
CVE-2025-11921
iStat Menus 7.10.4 - Local Privilege Escalation
Vulnerability Description
iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11921
Credits & Attribution
No credits recorded in the NVD database.
Affected Vendor
Bjango
View all reports →Affected Software
iStats
Vulnerable Versions:
7.10.4
Timeline
Official Publish:
November 24th, 2025
Last Modified:
December 19th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
MITRE ATT&CK TTPs
T1222
File and Directory Permissions Modification
Defense Evasion
T1574
Hijack Execution Flow
Privilege Escalation
T1005
Data from Local System
Collection
T1078
Valid Accounts
Persistence
T1562
Impair Defenses
Defense Evasion
T1190
Exploit Public-Facing Application
Initial Access
T1059
Command and Scripting Interpreter
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1105
Ingress Tool Transfer
Command and Control