{"id":"CVE-2026-4556","title":"Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC","summary":"Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a s…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"Extegrity","product":"com.extegrity.LogTool","affected":["com.extegrity.LogTool <= 25.12.28.0"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T15:17:17.723","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4556","references":[{"url":"https://pentraze.com/vulnerability-reports","label":"41c37e40-543d-43a2-b660-2fee83ea851a"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T15:13:31.604Z","slug":"CVE-2026-4556","body":"## Overview\n\nExam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to execute arbitrary commands with root privileges through LaunchSynchronous.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}