Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-732 CWE-77 |
|
| Metrics |
cvssV3_1
|
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anaconda
Anaconda miniconda3 Apple Apple macos |
|
| Vendors & Products |
Anaconda
Anaconda miniconda3 Apple Apple macos |
Wed, 17 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-18T18:52:37.437Z
Reserved: 2024-09-11T00:00:00.000Z
Link: CVE-2024-46062
Updated: 2025-12-18T16:10:35.641Z
Status : Awaiting Analysis
Published: 2025-12-17T19:16:00.300
Modified: 2025-12-18T19:16:20.760
Link: CVE-2024-46062
No data.
OpenCVE Enrichment
Updated: 2025-12-18T09:56:57Z