Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module
CVE-2020-7376

7.1HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
24 August 2020

What is CVE-2020-7376?

The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.

Affected Version(s)

Metasploit Framework 4.11.7 < 4.11.7*

Metasploit Framework 6.0.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported, and fixed, by bcoles.
.
CVE-2020-7376 : Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module