CVE-2015-3692Improper Access Control in Apple MAC OS X

Severity
6.8MEDIUMNVD
NVD6.0
EPSS
0.0%
top 89.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 3
Latest updateMay 17

Description

Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging root privileges.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.1 | Impact: 10.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j3vj-cfxc-hfjx: Apple Mac EFI before 2015-001, as used in OS X before 102022-05-17
GHSA
GHSA-v664-mrh9-gw5q: The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-d2022-05-13

📋Vendor Advisories

2
Apple
CVE-2015-3692: Mac EFI Security Update 2015-001
Apple
CVE-2015-3692: OS X Yosemite v10.10.4 and Security Update 2015-005