Groupnotes Inc. Videostream Mac client allows for privilege escalation to root account
Posted: Mon Feb 03, 2025 11:42 am
Groupnotes Inc. Videostream Mac client installs a LaunchDaemon that runs with root privileges. The daemon is vulnerable to a race condition that allows for arbitrary file writes. A low privileged attacker can escalate privileges to root on affected systems.
https://www.kb.cert.org/vuls/id/757109
https://www.kb.cert.org/vuls/id/757109