A local privilege escalation vulnerability exists in O+ Connect because it fails to validate the identity of the caller on the pipe interface.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.