Improper File Permissions in Fast CAD Reader for MacOS
CVE-2025-2098
Key Information:
- Status
- Vendor
- CVE Published:
- 26 March 2025
What is CVE-2025-2098?
The Fast CAD Reader application on MacOS exhibits improper file permissions (rwxrwxrwx), diverging from standard macOS security norms that dictate restricted access (drwxr-xr-x). This misconfiguration creates a significant security risk, allowing malicious users to exploit the vulnerability for Dylib Hijacking. The flaw poses a higher threat as it permits privilege escalation via guest accounts and other applications. Currently, all versions of the Fast CAD Reader are potentially affected, including version 4.1.5, as the vendor has not issued a response regarding this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fast CAD Reader MacOS 0 <= 4.1.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
