vendor:
Mac OS X
by:
Chromium Project
8.8
CVSS
HIGH
Mach_portal exploit
264
CWE
Product Name: Mac OS X
Affected Version From: 10.13.3
Affected Version To: 10.13.3
Patch Exists: YES
Related CWE: N/A
CPE: o:apple:mac_os_x:10.13.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Mac
2018
Mach_portal exploit
Mach_portal exploit is a vulnerability in the ReportCrash daemon which is responsible for making crash dumps of crashing userspace processes. It is possible to gain a reference to the task port by sending a message to ReportCrash via their exception ports (either task or host level) and then using the error path which drops a UREF on the task and thread port arguments.
Mitigation:
The vulnerability can be mitigated by disabling the ReportCrash daemon.