CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2017-13872 Apple macOS High Sierra Authentication Bypass Vulnerability (Zero Day)

2017年11月30日 1711点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

A vulnerability in macOS High Sierra operating system that allows an attacker with physical access to gain system administrator access without entering a password.
The security bug can be triggered via the authentication dialog box in macOS, which prompts you for an administrator's username and password.

QID Detection Logic (authenticated):
This QID looks for vulnerable version of Apple macOS High Sierra.

漏洞危害

If exploited, the attacker is authenticated into a 'root' account and is given full ability to view files and even reset or change passwords for pre-existing users on that machine.

解决方案

The vendor has confirmed the vulnerability but no patch has been released to specifically fix the vulnerability, however vendor has provided a workaround for this HT204012

0daybank

标签: 暂无
最后更新:2017年12月8日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me