An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6...
High severity
Unreviewed
Published
Jan 29, 2025
to the GitHub Advisory Database
•
Updated Jan 29, 2025
Description
Published by the National Vulnerability Database
Jan 28, 2025
Published to the GitHub Advisory Database
Jan 29, 2025
Last updated
Jan 29, 2025
An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handling privileged operations within the macOS DTEX Event Forwarder agent, fails to implement critical client validation during XPC interprocess communication (IPC). Specifically, the service does not verify the code requirements, entitlements, security flags, or version of any client attempting to establish a connection. This lack of proper logic validation allows malicious actors to exploit the service's methods via unauthorized client connections, and escalate privileges to root by abusing the DTConnectionHelperProtocol protocol's submitQuery method over an unauthorized XPC connection.
References