Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-3673Apple MAC OS X vulnerability

CWE-2645 documents5 sources
Severity
7.2HIGHNVD
EPSS
3.0%
top 13.37%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 3
Latest updateMay 17

Description

Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-2h38-rw9c-6j5p: Admin Framework in Apple OS X before 102022-05-17

💥Exploits & PoCs

2
Exploit-DB
Apple Mac OSX Entitlements - 'Rootpipe' Local Privilege Escalation (Metasploit)2015-08-31
Metasploit
Apple OS X Entitlements Rootpipe Privilege Escalation

📋Vendor Advisories

1
Apple
CVE-2015-3673: OS X Yosemite v10.10.4 and Security Update 2015-005