Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.
References
| Link | Resource |
|---|---|
| https://m8sec.dev/blog/privilege-escalation-macos-pkg-installers/ | Exploit Third Party Advisory |
| https://www.anaconda.com/docs/getting-started/anaconda/release/2024.x#anaconda-2024-06-1 | Release Notes |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-12-17 19:16
Updated : 2026-01-05 14:42
NVD link : CVE-2024-46060
Mitre link : CVE-2024-46060
CVE.ORG link : CVE-2024-46060
JSON object : View
Products Affected
anaconda
- anaconda3
apple
- macos
