CVE-2024-55503
Published: 15 January 2025
Summary
CVE-2024-55503 is a low-severity Untrusted Search Path (CWE-426) vulnerability in Termius Termius. Its CVSS base score is 3.3 (Low).
Operationally, exploitation aligns with the MITRE ATT&CK technique Dylib Hijacking (T1574.004); ranked in the top 15.6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-52779
Vulnerability details
An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES component.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
The vulnerability enables arbitrary code execution in Termius via DYLD_INSERT_LIBRARIES environment variable, facilitating dylib hijacking (T1574.004).
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.