Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-0342UNIX Hard Link in Apple MAC OS X

CWE-62UNIX Hard Link4 documents4 sources
Severity
2.1LOWNVD
EPSS
0.2%
top 57.31%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 2
Latest updateMay 1

Description

The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

NVDapple/mac_os_x28 versions+27
NVDapple/mac_os_x_server24 versions+23

Patches

🔴Vulnerability Details

1
GHSA
GHSA-6mpc-5vj6-8wr8: The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the2022-05-01

💥Exploits & PoCs

1
Exploit-DB
Apple Mac OSX - '.DS_Store' Arbitrary File Overwrite2005-02-07

📐Framework References

1
CWE
UNIX Hard Link