Sceawere
Vulnerability Detail
CVE-2026-4556UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Exam4 Privilege Escalation Command Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 2h ago
- Vendor
- Extegrity
- Product
- Exam4
- Attack Type
- CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to execute arbitrary commands with root privileges through LaunchSynchronous.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-28T15:17:17.723Z",
"pubdate": "2026-09-28T15:17:17.723Z",
"executiveSummary": "A critical local privilege escalation (LPE) vulnerability exists within the Exam4 application, specifically residing in the com.extegrity.LogTool privileged helper component.\nThe vulnerability is classified as command injection, occurring due to the improper sanitization of attacker-supplied inputs passed to a system command execution routine.\nSuccessful exploitation allows a local, unprivileged attacker to execute arbitrary commands with root privileges, bypassing system security boundaries.\nThe flaw manifests during XPC communication between the application and the privileged helper. By invoking the vulnerable [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method, an attacker can manipulate parameters to inject malicious shell commands.\nThis vulnerability poses a significant risk to system integrity and confidentiality, as it grants complete control over the affected system to an attacker with local access.\nExploitation requires no remote network access, relying strictly on local interaction with the XPC interface.",
"technicalDetails": "The vulnerability is rooted in the com.extegrity.LogTool component, which operates with elevated system privileges to perform logging operations. The application interface uses XPC (Cross-Process Communication) to request services from this helper tool.\nThe attack vector is identified within the [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method. Analysis indicates that this method takes arguments from the XPC message and incorporates them directly into a call to the syslog command without undergoing necessary input validation or sanitization routines.\nThe root cause is an insecure implementation of command construction, where the helper tool acts as a confused deputy. By providing malformed or malicious strings as parameters, an attacker can escape the intended command context and append arbitrary shell commands.\nThe attack flow follows a structured exploitation path: First, an attacker interacts with the com.extegrity.LogTool XPC service. Second, the attacker invokes the [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] function, passing a crafted payload designed to terminate the intended command and initiate a secondary malicious process. Third, because the helper runs with root privileges, the injected command is executed within the root security context via LaunchSynchronous.\nThe lack of parameterization or the use of safe execution APIs (such as execve with isolated arguments) allows the shell to interpret the injected control characters, resulting in command concatenation or execution of arbitrary binaries.\nThe impact of this vulnerability is total system compromise. Since the malicious commands execute with root privileges, an attacker can bypass all file system permissions, install persistent backdoors, dump memory, or exfiltrate sensitive data. The vulnerability is strictly local, meaning the attacker must already possess a foothold on the system to interface with the XPC service, though this is trivial for any authenticated user on a shared system or a compromised local account."
}