CVE ID | CVE-2025-2098 |
Publication date | 26 March 2025 |
Vendor | Beijing Honghu Yuntu Technology |
Product | Fast CAD Reader |
Vulnerable versions | All through 4.1.5 |
Vulnerability type (CWE) | Incorrect Privilege Assignment (CWE-266) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Fast CAD Reader (Beijing Honghu Yuntu Technology) application and participated in coordination of its disclosure.
Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. The vulnerability CVE-2025-2098 allows for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation.
This issue affects Fast CAD Reader in possibly all versions since the vendor has not responded to our messages. The tested version was 4.1.5.
Credits
We thank Karol Mazurek from AFINE for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.