Claris Fixes Dylib Hijacking Vulnerability in FileMaker Pro and Claris Pro
CVE-2023-42920

7.8HIGH

Key Information:

Vendor

Claris

Vendor
CVE Published:
19 March 2024

What is CVE-2023-42920?

Claris International has addressed a vulnerability in their FileMaker Pro.app and Claris Pro.app products that could allow dylib hijacking on macOS systems. This vulnerability poses a risk as it may enable unauthorized access and the execution of malicious code through the improper handling of dynamic libraries. Users are urged to update their software to the latest versions to mitigate any potential risks associated with this issue. For more information on security updates and practices, please refer to the Claris support documentation.

Affected Version(s)

FileMaker Pro < 20.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.