CVE-2015-1130highunder attackCWE-59

CVE-2015-1130

Published · Updated

86Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.8epss 9.9%
from disclosure to weapon0 days
Published on NVDApr 10
1st PoCApr 9
metasploitApr 9
CISA KEV+2498d
exploitation probability
9.9%top 5% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
Action required by CISAfederal deadline: 2022-08-10

Apply updates per vendor instructions.

In short

A flaw in Apple OS X's Admin Framework allows local users to bypass authentication checks and gain administrator privileges without proper authorization. This is a privilege escalation vulnerability that affects systems before version 10.10.3.

Technical detail

The XPC (inter-process communication) implementation in the Admin Framework contains an authentication bypass vulnerability (CWE-59: improper link resolution) that allows authenticated local users to escalate privileges to admin level. The attack requires local access and occurs through unspecified XPC message handling vectors in the framework's privilege checking logic.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.