Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allows attackers to execute arbitrary commands via unauthorized access to the Agent service.  This has been remediated in Work Desktop for Mac version 10.8.2.33.
History

Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions below 10.8.2.33 allows attackers to execute arbitrary commands via unauthorized access to the Agent service. Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allows attackers to execute arbitrary commands via unauthorized access to the Agent service.  This has been remediated in Work Desktop for Mac version 10.8.2.33.

Thu, 17 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions below 10.8.2.33 allows attackers to execute arbitrary commands via unauthorized access to the Agent service.
Title Command Injection in iManage Work Desktop for Mac's Agent Service
Weaknesses CWE-346
CWE-668
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: iManage

Published:

Updated: 2025-04-17T19:10:42.989Z

Reserved: 2025-04-15T18:23:36.913Z

Link: CVE-2025-3651

cve-icon Vulnrichment

Updated: 2025-04-17T19:10:38.580Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-17T15:15:58.620

Modified: 2025-04-17T20:21:48.243

Link: CVE-2025-3651

cve-icon Redhat

No data.