The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2020-0028.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2020-12-16 07:15
Updated : 2022-06-13 08:47
NVD link : CVE-2020-4008
Mitre link : CVE-2020-4008
JSON object : View
CWE
                Products Affected
                apple
- macos
 
vmware
- carbon_black_cloud
 


