CVE-2010-0512Apple MAC OS X vulnerability

CWE-2644 documents4 sources
Severity
9.3CRITICALNVD
EPSS
0.4%
top 38.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMay 2

Description

The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDapple/mac_os_x_server10.6.0, 10.6.1, 10.6.2+2
NVDapple/mac_os_x10.6.0, 10.6.1, 10.6.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5pm6-mxvg-938j: The Accounts Preferences implementation in Apple Mac OS X 102022-05-02
CVEList
CVE-2010-0512: The Accounts Preferences implementation in Apple Mac OS X 102010-03-30

💥Exploits & PoCs

1
Exploit-DB
PHP-Fusion Teams Structure Infusion Addon - SQL Injection2011-01-17
CVE-2010-0512 — Apple MAC OS X vulnerability | cvebase