Vulnerability record · CVE-2012-4284 · published 10 January 2020
CVE-2012-4284: Viscosity setuid helper path validation privilege escalation
Sparklabs · Viscosity
Viscosity 1.4.1 on Mac OS X ships a setuid-set ViscosityHelper binary that fails to properly validate path names. Because the helper runs with elevated privileges, this flaw lets an attacker execute arbitrary code in that privileged context. The record does not specify the exact validation routine or the affected code path beyond the helper binary.
Description
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw yields unauthenticated arbitrary code execution with a critical CVSS score and public exploit code, but it is not in KEV and the record lacks fixed-version detail.
What it is
Viscosity 1.4.1 on Mac OS X ships a setuid-set ViscosityHelper binary that fails to properly validate path names. Because the helper runs with elevated privileges, this flaw lets an attacker execute arbitrary code in that privileged context. The record does not specify the exact validation routine or the affected code path beyond the helper binary.
Impact
An attacker who can reach the helper gains arbitrary code execution with the privileges of the setuid binary, which on a setuid root helper means full root compromise of the host.
Attack surface
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N, so the flaw is network reachable with no authentication and no user interaction required. The description frames it as exploitable by a remote malicious user, though the underlying issue is in a local setuid helper, so the practical reachability depends on how that helper is invoked.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.69523 (99.3rd percentile), indicating high predicted exploitation activity. Multiple references are tagged Exploit, including Exploit-DB 24579 and a Packet Storm advisory, so public exploit code exists.
What to do
- Upgrade Viscosity to a version later than 1.4.1 per the vendor release notes; the record does not enumerate fixed versions.
- If upgrade is not possible, remove or restrict the setuid bit on the ViscosityHelper binary and gate its invocation.
- Restrict local and network access to the helper so only trusted users or processes can invoke it.
- Monitor for unexpected child processes spawned by ViscosityHelper and alert on privileged execution from it.
Detection
- Audit macOS hosts for the ViscosityHelper binary and confirm whether the setuid bit is set.
- Alert on ViscosityHelper spawning shells or unexpected binaries, especially as root.
- Review process lineage where ViscosityHelper is the parent of command interpreters or scripting runtimes.
- Track Viscosity version inventory to find hosts still running 1.4.1.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.exploit-db.com/exploits/24579 | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/55002 | Third Party AdvisoryVDB Entry |
| https://packetstormsecurity.com/files/120643/Viscosity-setuid-set-ViscosityHelper-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.sparklabs.com/viscosity/releasenotes/mac/ | Release NotesVendor Advisory |
| http://www.exploit-db.com/exploits/24579 | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/55002 | Third Party AdvisoryVDB Entry |
| https://packetstormsecurity.com/files/120643/Viscosity-setuid-set-ViscosityHelper-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.sparklabs.com/viscosity/releasenotes/mac/ | Release NotesVendor Advisory |
Track CVE-2012-4284 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4284), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.