CVE-2021-30657
published 2021-09-08CVE-2021-30657: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious…
PriorityP181medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
68.53%
99.3th percentile
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | 10.15 – 10.15.5 | — |
| apple | macos | >= 11.0 < 11.3 | 11.3 |
| apple | macos | >= unspecified < 11.3 | 11.3 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-002_catalina | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/browser/osx_gatekeeper_bypass.rb↗
- →Detect macOS .app bundles delivered as ZIP archives that are missing an Info.plist file — this is the core bypass mechanism for CVE-2021-30657 on macOS < 11.3. ↗
- →Monitor Safari's automatic ZIP extraction behaviour: if a ZIP containing a .app bundle (without Info.plist) is downloaded via Safari, it is auto-extracted and can be launched without a Gatekeeper prompt — alert on .app execution immediately following a Safari download event. ↗
- →Alert on .app bundles launched from the Downloads directory that lack a com.apple.quarantine extended attribute AND have no Info.plist — both conditions together indicate a likely Gatekeeper bypass attempt. ↗
- →The vulnerable component is System Preferences on macOS; monitor for unexpected process spawning from System Preferences or Gatekeeper-related processes (syspolicyd) on macOS versions below Big Sur 11.3 / Security Update 2021-002 Catalina. ↗
- ·The bypass only affects macOS versions below Big Sur 11.3 and unpatched Catalina (pre Security Update 2021-002). Systems running 11.3+ or with the Catalina security update applied are not vulnerable. ↗
- ·Apple confirmed active in-the-wild exploitation of this vulnerability at time of disclosure; treat any unpatched macOS endpoint as actively at risk. ↗
- ·The Metasploit module covers two CVEs (CVE-2021-30657 and CVE-2022-22616); ensure detections are scoped correctly — the no-Info.plist ZIP delivery technique maps specifically to CVE-2021-30657. ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vulncheck5.5MEDIUM
cisa5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple macOS Unspecified Vulnerability
cisa·2021-11-03·CVSS 5.5
CVE-2021-30657 [MEDIUM] CWE-862 Apple macOS Unspecified Vulnerability
Vulnerability: Apple macOS Unspecified Vulnerability
Affected: Apple macOS
Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-30657
Remediation Due Date: 2021-11-17
Apple
CVE-2021-30657: Security Update 2021-002 Catalina
vendor_apple·2021-04-26·CVSS 5.5
CVE-2021-30657 [MEDIUM] CVE-2021-30657: Security Update 2021-002 Catalina
Apple Security Update: About the security content of Security Update 2021-002 Catalina
Product: Security Update 2021-002 Catalina
CVE: CVE-2021-30657
Component: System Preferences
Impact: A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited.
Description: A logic issue was addressed with improved state management.
Apple
CVE-2021-30657: macOS Big Sur 11.3
vendor_apple·2021-04-26·CVSS 5.5
CVE-2021-30657 [MEDIUM] CVE-2021-30657: macOS Big Sur 11.3
Apple Security Update: About the security content of macOS Big Sur 11.3
Product: macOS Big Sur
Version: 11.3
CVE: CVE-2021-30657
Component: System Preferences
Impact: A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited.
Description: A logic issue was addressed with improved state management.
GHSA
GHSA-4f6h-9vp6-5p6r: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2021-30657 [MEDIUM] CWE-494 GHSA-4f6h-9vp6-5p6r: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..
VulnCheck
Apple macOS Unspecified Vulnerability
vulncheck·2021·CVSS 5.5
CVE-2021-30657 [MEDIUM] CWE-862 Apple macOS Unspecified Vulnerability
Apple macOS Unspecified Vulnerability
Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.
Affected: Apple MacOS X
Required Action: Apply updates per vendor instructions.
Exploitation References: https://support.apple.com/kb/HT212325; https://support.apple.com/kb/HT212326; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/5a5cb257b016
Remediation Due: 2021-11-17
No detection rules found.
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
2021-09-08
Published
2021-11-03
Added to CISA KEV
Exploited in the wild