9.3
CVSSv2

CVE-2020-14977

Published: 23/06/2020 Updated: 21/07/2021
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an malicious user to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f-secure safe 17.7