Code Injection Vulnerability in Logitech Options Plus Users can Execute Arbitrary Code
CVE-2024-8258

7.8HIGH

Key Information:

Vendor

Logitech

Vendor
CVE Published:
10 September 2024

What is CVE-2024-8258?

Logitech Options Plus for macOS is exposed to a code injection vulnerability caused by improper management of Electron Fuses. This flaw allows attackers to manipulate the Electron Fuses configuration, potentially leading to the execution of arbitrary code. The vulnerability arises from insufficient validation in the generation control of code, endangering user systems and data integrity. Mitigating this issue is critical to maintaining secure user environments.

Affected Version(s)

Logitech Options Plus MacOS 1.60.496306 < 1.70

Logitech Options Plus MacOS 1.70

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave F - https://hackerone.com/dave23p
.