CVE-2017-16895 Information
Feb 14, 2021
cve
Description
The (1) arq_updater (2) arqcommitter (3) standardrestorer (4) arqglacierrestorer and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://m4.rkw.io/blog/cve201716895-local-root-privesc-in-arq-backup–597.html https://www.arqbackup.com/blog/arq-mac-import-security-update/ https://www.exploit-db.com/exploits/43216/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: