SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-40531

Sketch before 75 allows library feeds to be used to bypass file quarantine.

CRITICAL 9.8EPSS 32.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 32.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
32.77% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
sketch/sketch
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.