CVE-2007-0345
published 2007-01-18CVE-2007-0345: The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC…
PriorityP416medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.41%
33.9th percentile
The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://projects.info-pull.com/moab/MOAB-15-01-2007.htmlhttp://www.osvdb.org/32700http://www.osvdb.org/32701http://www.osvdb.org/32702https://exchange.xforce.ibmcloud.com/vulnerabilities/31530https://www.exploit-db.com/exploits/3136http://projects.info-pull.com/moab/MOAB-15-01-2007.htmlhttp://www.osvdb.org/32700http://www.osvdb.org/32701http://www.osvdb.org/32702https://exchange.xforce.ibmcloud.com/vulnerabilities/31530https://www.exploit-db.com/exploits/3136
2007-01-18
Published