216.73.216.233

CVE-2024-13177

· Published 15/04/2025 16:15 · Modified 15/04/2025 18:39

Labels: CVE-2024-13177 2025-04-15CVE-2024-13177CWE-610[email protected]

Essential information

Published
15/04/2025 16:15
Modified
15/04/2025 18:39
Author
Creator
CVSS
5.2 MEDIUM (v3) 5.2 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the path of the file “nsinstallation”. A standard user could potentially create a symlink of the file “nsinstallation” to escalate the privileges of a different file on the system. This issue affects Netskope Client: before 123.0, before 117.1.11.2310, before 120.1.10.2306.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
netskope / netskope client cpe:2.3:a:netskope:netskope_client:<123.0:*:*:*:*:*:*:*
netskope / netskope client cpe:2.3:a:netskope:netskope_client:<117.1.11.2310:*:*:*:*:*:*:*
netskope / netskope client cpe:2.3:a:netskope:netskope_client:<120.1.10.2306:*:*:*:*:*:*:*

References