Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation. This issue affects Fast CAD Reader in possibly all versions since the vendor has not responded to our messages. The tested version was 4.1.5
Metrics
Affected Vendors & Products
References
History
Wed, 26 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 26 Mar 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation. This issue affects Fast CAD Reader in possibly all versions since the vendor has not responded to our messages. The tested version was 4.1.5 | |
Title | Dylib Hijacking in Fast CAD Reader | |
Weaknesses | CWE-266 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-03-26T15:23:42.768Z
Updated: 2025-03-26T15:49:49.578Z
Reserved: 2025-03-07T15:46:28.447Z
Link: CVE-2025-2098

Updated: 2025-03-26T15:49:45.944Z

Status : Received
Published: 2025-03-26T16:15:23.540
Modified: 2025-03-26T16:15:23.540
Link: CVE-2025-2098

No data.