Microsoft AutoUpdate Elevation of Privilege Vulnerability

Vulnerability

A vulnerability allowing local privilege escalation has been identified in Microsoft AutoUpdate (MAU) for Mac. This issue arises from improper link resolution before file access, which could enable an authorized attacker to replace a legitimate installer with a malicious one. When the victim executes the altered installer, the attacker could gain elevated privileges, potentially allowing commands to be executed as Root.

Impact

Exploitation of this vulnerability could allow an attacker to elevate privileges to Root in the target environment.

Reproduction

To reproduce this vulnerability, an authorized user can download an installer via Microsoft AutoUpdate. Before executing the installer, an attacker could intercept the download and replace it with a malicious version. Once the user runs the modified installer, the attacker could exploit the vulnerability to gain elevated privileges.

Remediation

Users can download the security update for Microsoft AutoUpdate for Mac from the Microsoft Update Catalog.

Added: Sep 9, 2025, 5:44 PM
Updated: Sep 9, 2025, 5:44 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
7.5
exploitability
3.6
remediation
7.7
relevance
0.5
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.