{"api_version":"1","generated_at":"2026-07-23T04:57:31+00:00","cve":"CVE-2008-2830","urls":{"html":"https://cve.report/CVE-2008-2830","api":"https://cve.report/api/cve/CVE-2008-2830.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2830","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2830"},"summary":{"title":"CVE-2008-2830","description":"Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-06-23 20:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html","name":"http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2008-07-31 Security Update 2008-005","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/1905/references","name":"http://www.vupen.com/english/advisories/2008/1905/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43294","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43294","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/29831","name":"http://www.securityfocus.com/bid/29831","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Apple Mac OS X AppleScript ARDAgent Shell Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.apple.com/archives/security-announce//2008//Sep/msg00006.html","name":"http://lists.apple.com/archives/security-announce//2008//Sep/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2008-09-16 Apple Remote Desktop 3.2.2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://it.slashdot.org/it/08/06/18/1919224.shtml","name":"http://it.slashdot.org/it/08/06/18/1919224.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Slashdot | Mac OS X Root Escalation Through AppleScript","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30776","name":"http://secunia.com/advisories/30776","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Mac OS X ARDAgent Privilege Escalation Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1020345","name":"http://www.securitytracker.com/id?1020345","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mac OS X Apple Remote Desktop Agent Lets Local Users Gain Root Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2830","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2830","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2830","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2830","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:14:14.687Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2008-1905","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1905/references"},{"name":"APPLE-SA-2008-07-31","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html"},{"name":"30776","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30776"},{"name":"apple-macosx-ardagent-command-execution(43294)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43294"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://it.slashdot.org/it/08/06/18/1919224.shtml"},{"name":"29831","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/29831"},{"name":"1020345","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1020345"},{"name":"APPLE-SA-2008-09-16","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce//2008//Sep/msg00006.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-06-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2008-1905","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1905/references"},{"name":"APPLE-SA-2008-07-31","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html"},{"name":"30776","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30776"},{"name":"apple-macosx-ardagent-command-execution(43294)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43294"},{"tags":["x_refsource_MISC"],"url":"http://it.slashdot.org/it/08/06/18/1919224.shtml"},{"name":"29831","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/29831"},{"name":"1020345","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1020345"},{"name":"APPLE-SA-2008-09-16","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce//2008//Sep/msg00006.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-2830","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2008-1905","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/1905/references"},{"name":"APPLE-SA-2008-07-31","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html"},{"name":"30776","refsource":"SECUNIA","url":"http://secunia.com/advisories/30776"},{"name":"apple-macosx-ardagent-command-execution(43294)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43294"},{"name":"http://it.slashdot.org/it/08/06/18/1919224.shtml","refsource":"MISC","url":"http://it.slashdot.org/it/08/06/18/1919224.shtml"},{"name":"29831","refsource":"BID","url":"http://www.securityfocus.com/bid/29831"},{"name":"1020345","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1020345"},{"name":"APPLE-SA-2008-09-16","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce//2008//Sep/msg00006.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-2830","datePublished":"2008-06-23T20:00:00.000Z","dateReserved":"2008-06-23T00:00:00.000Z","dateUpdated":"2024-08-07T09:14:14.687Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-06-23 20:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*","matchCriteriaId":"0760FDDB-38D3-4263-9B4D-1AF5E613A4F9"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*","matchCriteriaId":"D2442D35-7484-43D8-9077-3FDF63104816"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2830","Ordinal":"1","Title":"CVE-2008-2830","CVE":"CVE-2008-2830","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2830","Ordinal":"1","NoteData":"Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent.","Type":"Description","Title":"CVE-2008-2830"},{"CveYear":"2008","CveId":"2830","Ordinal":"2","NoteData":"2008-06-23","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"2830","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}