CVE-2015-3708
published 2015-07-03CVE-2015-3708: kextd in kext tools in Apple OS X before 10.10.4 allows attackers to write to arbitrary files via a crafted app that conducts a symlink attack.
PriorityP341high8.8CVSS 2.0
AVNACMAuNCNICAC
EPSS
1.62%
73.5th percentile
kextd in kext tools in Apple OS X before 10.10.4 allows attackers to write to arbitrary files via a crafted app that conducts a symlink attack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.3 | — |
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pr99-p5f4-p6f9: kextd in kext tools in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2015-3708 [HIGH] GHSA-pr99-p5f4-p6f9: kextd in kext tools in Apple OS X before 10
kextd in kext tools in Apple OS X before 10.10.4 allows attackers to write to arbitrary files via a crafted app that conducts a symlink attack.
Apple
CVE-2015-3708: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 8.8
CVE-2015-3708 [HIGH] CVE-2015-3708: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-3708
Component: CVE-ID
Impact: A local user may be able to load unsigned kernel extensions
Description: A time-of-check time-of-use (TOCTOU) race condition condition existed while validating the paths of kernel extensions. This issue was addressed through improved checks to validate the path of the kernel extensions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://support.apple.com/kb/HT204942http://www.securityfocus.com/bid/75493http://www.securitytracker.com/id/1032760http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://support.apple.com/kb/HT204942http://www.securityfocus.com/bid/75493http://www.securitytracker.com/id/1032760
2015-07-03
Published