Apple Remote Desktop Administrator Privilege Escalation Vulnerability
BID:11554
Info
Apple Remote Desktop Administrator Privilege Escalation Vulnerability
| Bugtraq ID: | 11554 |
| Class: | Design Error |
| CVE: |
CVE-2004-0962 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 27 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery of this vulnerability is credited to Andrew Nakhla. |
| Vulnerable: |
Apple Remote Desktop 2.1 Apple Remote Desktop 2.0 |
| Not Vulnerable: |
Apple Remote Desktop 2.1 |
Discussion
Apple Remote Desktop Administrator Privilege Escalation Vulnerability
A privilege escalation vulnerability affects Apple Remote Desktop Administrator. The issue is due to a design error that fails to activate applications with the correct privileges.
This issue may allow a local attacker to gain superuser privileges on the affected computer.
A privilege escalation vulnerability affects Apple Remote Desktop Administrator. The issue is due to a design error that fails to activate applications with the correct privileges.
This issue may allow a local attacker to gain superuser privileges on the affected computer.
Exploit / POC
Apple Remote Desktop Administrator Privilege Escalation Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Apple Remote Desktop Administrator Privilege Escalation Vulnerability
Solution:
Apple has released an advisory (APPLE-SA-2004-10-27) and a fix to address this vulnerability.
Apple Remote Desktop 2.0
Solution:
Apple has released an advisory (APPLE-SA-2004-10-27) and a fix to address this vulnerability.
Apple Remote Desktop 2.0
-
Apple SecurityUpdate2004-10-27.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04934&plat form=osx&method=sa/SecurityUpdate2004-10-27.dmg
References
Apple Remote Desktop Administrator Privilege Escalation Vulnerability
References:
References: