Privilege Escalation Vulnerability in CatoNetworks CatoClient for macOS
CVE-2025-3886

5.7MEDIUM

Key Information:

Vendor
CVE Published:
27 April 2025

What is CVE-2025-3886?

A security issue in the CatoNetworks CatoClient prior to version 5.8.0 allows attackers to exploit the PrivilegedHelperTool component. This exploitation can lead to privilege escalation and the potential for a time-of-check to time-of-use (TOCTOU) race condition, enabling malicious actors to execute unauthorized actions within the affected system. Users are strongly recommended to upgrade to the latest version to mitigate this risk and enhance their security posture.

Affected Version(s)

SDP Client MacOS 0 < 5.8.0

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.