CVE-2017-15357
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
01/12/2017
Last modified:
20/04/2025
Description
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:arqbackup:arq:*:*:*:*:*:macos:*:* | 5.9.7 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://m4.rkw.io/blog/cve201715357-local-root-privesc-in-arq-backup--596.html
- https://www.arqbackup.com/download/arq5_release_notes.html
- https://www.exploit-db.com/exploits/43218/
- https://m4.rkw.io/blog/cve201715357-local-root-privesc-in-arq-backup--596.html
- https://www.arqbackup.com/download/arq5_release_notes.html
- https://www.exploit-db.com/exploits/43218/