vendor:
MacOS 10.13
by:
Fabiano Anemone
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: MacOS 10.13
Affected Version From: iOS 11.4.1 / MacOS 10.13.6
Affected Version To: iOS 11.4.1 / MacOS 10.13.6
Patch Exists: YES
Related CWE: Not assigned
CPE: o:apple:mac_os_x:10.13.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: iOS / MacOS
2018
MacOS 10.13 – ‘workq_kernreturn’ Denial of Service (PoC)
This exploit is a proof of concept for a denial of service vulnerability in MacOS 10.13 and iOS 11. The exploit uses the workq_kernreturn syscall to cause a panic in the system. The exploit is triggered by calling the workq_kernreturn syscall with the WQOPS_THREAD_WORKLOOP_RETURN option and any non-zero address.
Mitigation:
The vulnerability has been fixed in Mojave.