CVE-2017-7149
Summary
| CVE | CVE-2017-7149 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-23 01:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple macOS CVE-2017-7149 Local Unauthorized Access Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Crazy but true – Apple’s “show hint” button reveals your actual password – Naked Security | MISC | nakedsecurity.sophos.com | Exploit, Technical Description, Third Party Advisory |
| New macOS High Sierra vulnerability exposes the password of an encrypted APFS container | MISC | hackernoon.com | Exploit, Third Party Advisory |
| Apple macOS/OS X Disk Utility Hint Field Lets Local Users View the Password for an Encrypted APFS Volume - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| About the security content of macOS High Sierra 10.13 Supplemental Update - Apple Support | CONFIRM | support.apple.com | Vendor Advisory |
| Dumb bug of the week: Apple's macOS reveals your encrypted drive's password in the hint box • The Register | MISC | www.theregister.co.uk | Exploit, Press/Media Coverage, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.