Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-17T18:48:34.954Z
Reserved: 2024-09-11T00:00:00.000Z
Link: CVE-2024-46062
No data.
Status : Received
Published: 2025-12-17T19:16:00.300
Modified: 2025-12-17T19:16:00.300
Link: CVE-2024-46062
No data.
OpenCVE Enrichment
No data.