BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2.

Project Subscriptions

Vendors Products
Dr.buho Subscribe
Buhontfs Subscribe
Buhontfs Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 15 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
References

Mon, 05 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Drbuho
Drbuho buhontfs
CPEs cpe:2.3:a:drbuho:buhontfs:1.3.2:*:*:*:*:macos:*:*
Vendors & Products Drbuho
Drbuho buhontfs
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 23 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 19 Dec 2025 16:00:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Thu, 18 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Description BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2.
Title BuhoNTFS 1.3.2 - Local Privilege Escalation
First Time appeared Dr.buho
Dr.buho buhontfs
Weaknesses CWE-732
CPEs cpe:2.3:a:dr.buho:buhontfs:1.3.2:*:macos:*:*:*:*:*
Vendors & Products Dr.buho
Dr.buho buhontfs
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-01-15T20:10:24.643Z

Reserved: 2025-11-26T01:00:32.238Z

Link: CVE-2025-13733

cve-icon Vulnrichment

Updated: 2025-12-18T19:04:38.244Z

cve-icon NVD

Status : Modified

Published: 2025-12-12T16:15:42.493

Modified: 2026-01-15T21:16:02.280

Link: CVE-2025-13733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses