CVE-2023-27529

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
25/05/2023
Last modified:
16/01/2025

Description

Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the installer, arbitrary code may be executed with the root privilege.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wacom:tablet_driver_installer:*:*:*:*:*:*:*:* 6.4.2-1 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*