• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

CleanMyMac X software spotted with several privilege escalation vulnerabilities

{{postValue.id}}

Recently, a lot of privilege escalation vulnerabilities in MacPaw’s CleanMyMac X software.

The vulnerabilities could allow attackers to gain local access to victims’ systems and modify the file system as root. MacPaw’s CleanMyMac X software frees up the disk space on users’ machines by scanning for unused and unnecessary files and deleting them.

Recently, a team of researchers found out several privilege escalation vulnerabilities in the software which could allow attackers to gain local access to victims’ machines. The attackers could then modify the file system as root.

Researchers from Cisco Talos detected 13 privilege escalation vulnerabilities in CleanMyMac X software. Talos has tested and confirmed that Clean My Mac X, version 4.04 is affected by all of these vulnerabilities.

Delete files from the root file system

One of the privilege escalation vulnerability arises in the ‘moveItemAtPath’ function of the helper protocol as CleanMyMac X software improperly validates the inputs. This vulnerability could allow non-root users to delete files from the root file system.

Similar vulnerabilities that arise in ‘moveToTrashItemAtPath’, ‘removeItemAtPath’, ‘truncateFileAtPath’, and ‘removeKextAtPath’ of the helper could allow non-root users to cross privilege boundary and delete files from the root file system.

Tags:
anettejoseph
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 0 )

No questions available

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Lucas ?
Various options in Top command

Am using Top command only to view the load average, what are the various options in Top command..??

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.