vendor:
Mac OS X
by:
Unknown
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Mac OS X
Affected Version From: Mac OS X 10.3
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2004-1557
CPE: o:apple:mac_os_x
Platforms Tested: Mac OS X
Unknown
Mac OS X help: Protocol Remote Code Execution Vulnerability
The vulnerability exists due to the 'help:' protocol implemented by the Mac OS X help application. The 'help:' protocol can be invoked remotely by the Safari web browser, allowing an attacker to craft a malicious link and entice a user to follow the link in order to execute script code via the help application. This can be exploited to execute arbitrary code with minimal user interaction.
Mitigation:
To mitigate this vulnerability, users are advised to update to the latest version of Mac OS X. Additionally, users should exercise caution when clicking on unfamiliar links or accessing unknown websites.