CVE-2018-4251 — Incorrect Permission Assignment in Apple MAC OS X
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 65.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateMay 13
Description
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" component. It allows attackers to modify the EFI flash-memory region that a crafted app that has root access.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
1📋Vendor Advisories
1Apple▶
CVE-2018-4251: macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan↗2018-06-01
📐Framework References
1💬Community
1Bugzilla▶
CVE-2018-8036 pdfbox: Infinite loop in AFMParser.java allows for out of memory erros via crafted PDF↗2018-07-03