Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-17T18:42:52.736Z
Reserved: 2024-09-11T00:00:00.000Z
Link: CVE-2024-46060
No data.
Status : Received
Published: 2025-12-17T19:16:00.160
Modified: 2025-12-17T19:16:00.160
Link: CVE-2024-46060
No data.
OpenCVE Enrichment
No data.