MacOS X NetInfo Manager Privilege Escalation Vulnerability
BID:3439
Info
MacOS X NetInfo Manager Privilege Escalation Vulnerability
| Bugtraq ID: | 3439 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 17 2001 12:00AM |
| Updated: | Oct 17 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on October 17th, 2001 by rotaiv <[email protected]>. |
| Vulnerable: |
Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 |
| Not Vulnerable: | |
Discussion
MacOS X NetInfo Manager Privilege Escalation Vulnerability
MacOS X is prone to an issue which will allow a local attacker to gain root privileges on the host.
NetInfo Manager, which runs as root, does not drop superuser privileges when it spawns applications in the 'Recent Items' list. As a result, an attacker can have arbitrary programs executed with root privileges.
This problem is not exclusive to the 'Recent Items' list. The 'Services' menu is also prone to this issue.
MacOS X is prone to an issue which will allow a local attacker to gain root privileges on the host.
NetInfo Manager, which runs as root, does not drop superuser privileges when it spawns applications in the 'Recent Items' list. As a result, an attacker can have arbitrary programs executed with root privileges.
This problem is not exclusive to the 'Recent Items' list. The 'Services' menu is also prone to this issue.
Exploit / POC
MacOS X NetInfo Manager Privilege Escalation Vulnerability
There is no exploit required.
There is no exploit required.
References
MacOS X NetInfo Manager Privilege Escalation Vulnerability
References:
References: