CVE-2015-3692 — Improper Access Control in Apple MAC OS X
Severity
6.8MEDIUMNVD
NVD6.0
EPSS
0.0%
top 89.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3
Latest updateMay 17
Description
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging root privileges.
CVSS vector
AV:L/AC:L/C:C/I:C/A:CExploitability: 3.1 | Impact: 10.0