Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-27822.
PoCs published by Mykola Grymalyuk, h00die, including Metasploit module exploits/osx/local/packagekit_zshenv_privesc.
AI-analyzed exploit summary This Metasploit module exploits CVE-2024-27822, a privilege escalation vulnerability in macOS PackageKit where ZSH installer scripts inherit the user's environment and execute ~/.zshenv with root privileges. The exploit injects a payload into ~/.zshenv that triggers only when EUID=0, then uses a crafted PKG installer to escalate privileges.
Description
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.
Exploits (1)
This Metasploit module exploits CVE-2024-27822, a privilege escalation vulnerability in macOS PackageKit where ZSH installer scripts inherit the user's environment and execute ~/.zshenv with root privileges. The exploit injects a payload into ~/.zshenv that triggers only when EUID=0, then uses a crafted PKG installer to escalate privileges.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H