Apple Mac OS X IOBluetoothHCIController Local Privilege Escalation Vulnerability
BID:70894
Info
Apple Mac OS X IOBluetoothHCIController Local Privilege Escalation Vulnerability
| Bugtraq ID: | 70894 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 30 2014 12:00AM |
| Updated: | Oct 30 2014 12:00AM |
| Credit: | Roberto Paleari and Aristide Fattori |
| Vulnerable: |
Apple Mac OS X 10.9.5 Apple Mac OS X 10.9.4 |
| Not Vulnerable: |
Apple Mac OS X 10.10 |
Discussion
Apple Mac OS X IOBluetoothHCIController Local Privilege Escalation Vulnerability
Apple Mac OS X is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with root privileges.
Apple Mac OS X 10.9.4 and 10.9.5 are vulnerable.
Apple Mac OS X is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with root privileges.
Apple Mac OS X 10.9.4 and 10.9.5 are vulnerable.
Exploit / POC
Apple Mac OS X IOBluetoothHCIController Local Privilege Escalation Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Apple Mac OS X IOBluetoothHCIController Local Privilege Escalation Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Apple Mac OS X IOBluetoothHCIController Local Privilege Escalation Vulnerability
References:
References:
- Apple Mac OS X Homepage (Apple)
- Mac OS X local privilege escalation (IOBluetoothFamily) (Aristide Fattori)