CVE-2017-2675: Obdev Little Snitch

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. The vulnerability is related to the installation of the configuration file "at.obdev.littlesnitchd.plist" which gets installed to /Library/LaunchDaemons.

Affected products

  • Obdev Little Snitch: version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.1 only; …
  • Objective Development Little Snitch: version 3.6.2 only; version 3.6.3 only; version 3.6.4 only; version 3.7 only; version 3.7.1 only; version 3.7.2 only; …

Published 2017-04-06. Last modified 2026-06-17.