Improper File Permissions in Fast CAD Reader for MacOS
CVE-2025-2098
8.4HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 26 March 2025
What is CVE-2025-2098?
The Fast CAD Reader application on MacOS exhibits improper file permissions (rwxrwxrwx), diverging from standard macOS security norms that dictate restricted access (drwxr-xr-x). This misconfiguration creates a significant security risk, allowing malicious users to exploit the vulnerability for Dylib Hijacking. The flaw poses a higher threat as it permits privilege escalation via guest accounts and other applications. Currently, all versions of the Fast CAD Reader are potentially affected, including version 4.1.5, as the vendor has not issued a response regarding this issue.
Affected Version(s)
Fast CAD Reader MacOS 0 <= 4.1.5