DTEX DEC-M (DTEX Forwarder) version 6.1.1 contains a vulnerability in the com.dtexsystems.helper service on macOS. The service, which handles privileged operations, does not perform adequate validation of XPC clients. It fails to check code requirements, entitlements, security flags, or client version, allowing any process to connect. An attacker can exploit this by connecting to the service and invoking privileged methods, specifically abusing the DTConnectionHelperProtocol's submitQuery method, to escalate privileges to root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a local privilege escalation (LPE) proof-of-concept exploit for CVE-2024-55968, targeting the DTEX Event Forwarder agent (DEC-M) version 6.1.1 on macOS. The exploit is implemented in Objective-C (POC.m) and abuses the com.dtexsystems.helper XPC service, which fails to validate client connections. By connecting to this service and invoking the submitQuery method, the exploit attaches to the privileged /var/db/auth.db database, queries for the admin privilege ID, updates and inserts rules to escalate privileges, and detaches the database. This sequence enables the attacker to execute code as root. The repository consists of the exploit code and a README.md describing the vulnerability, affected product, and attack vector. The main fingerprintable endpoints are the com.dtexsystems.helper XPC mach service and the /var/db/auth.db file.
This repository contains a proof-of-concept (POC) local privilege escalation exploit for CVE-2024-55968, targeting DTEX Forwarder (DEC-M) version 6.1.1 on macOS. The exploit leverages a logic flaw in the com.dtexsystems.helper XPC service, which fails to validate client connections, allowing unauthorized local users to interact with privileged methods. The main exploit file, 'poc.m', is written in Objective-C and demonstrates how to connect to the vulnerable XPC service and issue SQL queries to the system's authorization database ('/var/db/auth.db'). By attaching the database, extracting the admin privilege rule ID, and updating/inserting rules, the exploit modifies authorization settings to escalate privileges to root. The repository structure is simple, consisting of a README.md (which documents the vulnerability and usage) and the exploit code (poc.m). No external network endpoints are involved; the attack is purely local and targets macOS systems running the vulnerable DTEX component.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.