CVE-2017-7149
published 2017-10-23CVE-2017-7149: An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows…
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.50%
39.9th percentile
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.13 | — |
| apple | macos_high_sierra_10.13_supplemental_update | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-7149: macOS High Sierra 10.13 Supplemental Update
vendor_apple·2017-10-05·CVSS 7.8
CVE-2017-7149 [HIGH] CVE-2017-7149: macOS High Sierra 10.13 Supplemental Update
Apple Security Update: About the security content of macOS High Sierra 10.13 Supplemental Update
Product: macOS High Sierra 10.13 Supplemental Update
CVE: CVE-2017-7149
Component: StorageKit
Impact: A local attacker may gain access to an encrypted APFS volume
Description: If a hint was set in Disk Utility when creating an APFS encrypted volume, the password was stored as the hint. This was addressed by clearing hint storage if the hint was the password, and by improving the logic for storing hints.
GHSA
GHSA-7c54-6w6x-g29v: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-13
CVE-2017-7149 [HIGH] GHSA-7c54-6w6x-g29v: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/101178http://www.securitytracker.com/id/1039513https://hackernoon.com/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79https://nakedsecurity.sophos.com/2017/10/05/urgent-update-your-mac-again-right-now/https://support.apple.com/HT208165https://www.theregister.co.uk/2017/10/05/apple_patches_password_hint_bug_that_revealed_password/http://www.securityfocus.com/bid/101178http://www.securitytracker.com/id/1039513https://hackernoon.com/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79https://nakedsecurity.sophos.com/2017/10/05/urgent-update-your-mac-again-right-now/https://support.apple.com/HT208165https://www.theregister.co.uk/2017/10/05/apple_patches_password_hint_bug_that_revealed_password/
2017-10-23
Published