vendor:
OSX
by:
David Kennedy
9,3
CVSS
HIGH
Privilege Escalation
N/A
CWE
Product Name: OSX
Affected Version From: OSX <= 10.8.4
Affected Version To: OSX <= 10.8.4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OSX
2013
OSX <= 10.8.4 Local Root Priv Escalation Root Reverse Shell
This exploit is a local privilege escalation vulnerability in OSX versions prior to 10.8.4. It allows an attacker to gain root access to the system by exploiting a flaw in the sudo command. The exploit works by setting the system time to a specific date and time, then running the sudo command with a malicious command. The malicious command will open a reverse shell to the attacker's IP address and port, allowing the attacker to gain root access to the system.
Mitigation:
Upgrade to OSX 10.8.4 or later.