Closed carolgschwend closed 2 years ago
It seems like there are lots of issues associated with the 12.5.1 macOS upgrade on M1, not just this one. Hang tight, we're working on it.
Also, this is a possible duplicate of #2793 and of #2798.
Osx.Exploit.CVE_2021_4034-9951522-2
This CVE doesn't seem relevant to macOS / Lima 🤔 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Also, this is a possible duplicate of #2793 and of #2798.
This seems to be the case.
Discussed in https://github.com/rancher-sandbox/rancher-desktop/discussions/2792
Our Cisco Secure Endpoint is flagging Rancher as CVE and preventing downloads.