Learn about CVE-2019-5013, a privilege escalation vulnerability in the Wacom driver's update helper service, allowing local users to execute arbitrary launchD agents. Find mitigation steps and preventive measures here.
A privilege escalation vulnerability was discovered in the Wacom driver's update helper service, specifically in the start/stopLaunchDProcess command of version 6.3.32-3. This vulnerability allows a local user to execute arbitrary launchD agents, requiring physical access to the affected machine.
Understanding CVE-2019-5013
This CVE involves a privilege escalation vulnerability in the Wacom driver's update helper service.
What is CVE-2019-5013?
CVE-2019-5013 is a privilege escalation vulnerability found in the Wacom driver's update helper service, affecting version 6.3.32-3. The vulnerability allows a local user to execute arbitrary launchD agents.
The Impact of CVE-2019-5013
The vulnerability has a CVSS base score of 7.1, indicating a high severity issue. It can lead to arbitrary code execution by a local user with physical access to the machine.
Technical Details of CVE-2019-5013
This section provides technical details of the vulnerability.
Vulnerability Description
The vulnerability exists in the start/stopLaunchDProcess command of the Wacom driver's update helper service. It allows a user-supplied string argument to execute launchctl under root context.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to mitigate and prevent exploitation of CVE-2019-5013.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates