CVE-2015-7016
published 2015-10-23CVE-2015-7016: The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, which allows…
PriorityP335high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
1.38%
69.4th percentile
The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, which allows attackers to bypass intended entitlement restrictions and gain privileges via a crafted developer-signed app.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.0 | — |
| apple | os_x_el_capitan_10.11.1_security_update_2015-004_yosemite_and_security_update_20 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c78q-5f5w-q68p: The MCX Application Restrictions component in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2015-7016 [HIGH] GHSA-c78q-5f5w-q68p: The MCX Application Restrictions component in Apple OS X before 10
The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, which allows attackers to bypass intended entitlement restrictions and gain privileges via a crafted developer-signed app.
Apple
CVE-2015-7016: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
vendor_apple·CVSS 7.6
CVE-2015-7016 [HIGH] CVE-2015-7016: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Product: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
CVE: CVE-2015-7016
Component: CVE-ID
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: Multiple memory corruption issues existed in DNS data parsing. These issues were addressed through improved bounds checking.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-23
Published