Improper File Permissions in Fast CAD Reader for MacOS
CVE-2025-2098

8.4HIGH

What is CVE-2025-2098?

The Fast CAD Reader application on MacOS exhibits improper file permissions (rwxrwxrwx), diverging from standard macOS security norms that dictate restricted access (drwxr-xr-x). This misconfiguration creates a significant security risk, allowing malicious users to exploit the vulnerability for Dylib Hijacking. The flaw poses a higher threat as it permits privilege escalation via guest accounts and other applications. Currently, all versions of the Fast CAD Reader are potentially affected, including version 4.1.5, as the vendor has not issued a response regarding this issue.

Affected Version(s)

Fast CAD Reader MacOS 0 <= 4.1.5

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Mazurek with AFINE
.