← Back

CVE-2025-55076

nvd nist
Published: Dec 3, 2025Modified: Dec 18, 2025

JSON object

Loading...
6.2
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.5 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges.

Affected (1)

Installation Manager
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.4.0
Running on/withPlatform Versions
Apple
Macos
All versions

References (1)

Timeline

No history available yet.