Anaconda3
cpe:2.3:a:anaconda:anaconda3:*:*:*:*:*:*:*
- < 2024.06-1
A local privilege escalation vulnerability has been identified in Anaconda3 macOS installers prior to version 2024.06-1. When installed outside the user's home directory, these installers create world-writable files that are executed with root privileges. This behavior allows a low-privileged user to inject arbitrary commands, potentially leading to unauthorized code execution as the root user.
Exploitation of this vulnerability allows for local privilege escalation, enabling a low-privileged user to execute commands with root privileges.
The vulnerability can be reproduced by installing Anaconda3 version 2024.02-1 or earlier on macOS, outside the user's home directory. During the installation, the package creates world-writable files that can be modified by low-privileged users. Once the injected commands are executed, they run with elevated permissions, achieving privilege escalation.
Users can upgrade to Anaconda3 version 2024.06-1 or later, where this vulnerability has been addressed by removing the `user_post_install.pkg` package.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.