Link Following Vulnerability Affects File Manipulation in HYPR Workforce Access on MacOS
CVE-2024-0068

7.1HIGH

Key Information:

Vendor

Hypr

Vendor
CVE Published:
29 February 2024

What is CVE-2024-0068?

An improper link resolution vulnerability exists in HYPR Workforce Access for MacOS that permits unauthorized file manipulation. This flaw allows an attacker to resolve links improperly, leading to potential security breaches and exploitation of sensitive files. The issue impacts versions of Workforce Access prior to 8.7.1, necessitating updates to safeguard against potential threats. Users are advised to check their software version and implement the latest security measures promptly.

Affected Version(s)

Workforce Access MacOS 0 < 8.7.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.