VYPR

ForkLift

by BinaryNights

CVEs (2)

  • CVE-2020-27192Nov 17, 2020
    risk 0.00cvss epss 0.00

    BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allowed a local attacker to inject code into ForkLift. This would allow the attacker to run malicious code with escalated privileges through ForkLift's helper tool.

  • CVE-2020-15349Nov 17, 2020
    risk 0.00cvss epss 0.00

    BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool implements an XPC interface that allows file operations to any process (copy, move, delete) as root and changing permissions.