Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-55968 PoC — DTEX DEC-M 安全漏洞

Source
Associated Vulnerability
Title:DTEX DEC-M 安全漏洞 (CVE-2024-55968)
Description:An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handling privileged operations within the macOS DTEX Event Forwarder agent, fails to implement critical client validation during XPC interprocess communication (IPC). Specifically, the service does not verify the code requirements, entitlements, security flags, or version of any client attempting to establish a connection. This lack of proper logic validation allows malicious actors to exploit the service's methods via unauthorized client connections, and escalate privileges to root by abusing the DTConnectionHelperProtocol protocol's submitQuery method over an unauthorized XPC connection.
Description
Exploit POC Code for CVE-2024-55968
Readme
# CVE-2024-55968
LPE Exploit POC Code for CVE-2024-55968

## Description
This repo hosts a POC to a critical logic vulnerability in the DTEX Event Reporting Service. DTEX is a unified insider risk management platform. 

In summary, the Event Reporting Service was found to not properly validate incoming interprocess connections. Lack of interprocess connection validation allows a malicious actor to execute highly privileged code in the context of the service, which runs with the highest privileges on the operating system.
File Snapshot

[4.0K] /data/pocs/df3c38b8fe01e778f59a0038a31e6c5ae4bb96a5 ├── [7.2K] POC.m └── [ 527] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →