CVE-2025-65843

7.7

Aquarius Desktop · Aquarius Desktop

Aquarius Desktop 3.0.069 for macOS suffers from an insecure file handling vulnerability where the application follows symbolic links during support archive generation, allowing unauthorized file access.

Executive summary

A local file handling vulnerability in Aquarius Desktop 3.0.069 for macOS allows an attacker to read or modify arbitrary files on the system, posing a significant risk to data confidentiality and integrity.

Vulnerability

The application utilizes a JUCE directory iterator that improperly follows symbolic links within the log directory. This allows an unauthenticated local attacker to plant symlinks to sensitive system files, which are then processed and exposed or modified during the support ZIP generation process.

Business impact

Successful exploitation of this vulnerability permits a local attacker to bypass filesystem restrictions, leading to unauthorized disclosure of sensitive data or modification of system files. Given the CVSS score of 7.7, this vulnerability represents a high risk to the organization, particularly when considering the potential for privilege escalation if the attacker targets root-owned files.

Remediation

Immediate Action: Users should restrict local access to the affected macOS workstations and monitor for any suspicious symbolic link creation within the user Library logs directory.

Proactive Monitoring: Security teams should audit the ~/Library/Logs/Aquarius directory for unexpected symlink activity or unauthorized access attempts to sensitive configuration files.

Compensating Controls: Implement host-based access control policies to limit the ability of non-privileged users to create symlinks in sensitive application directories.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a high risk due to the potential for unauthorized file access and privilege escalation on macOS systems. Administrators should prioritize identifying instances of Aquarius Desktop 3.0.069 in their environment and restrict local user permissions while awaiting a formal security patch from the vendor.

Sources