vendor:
Mac OS X
by:
Emil Kvarnhammar, joev
7.5
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Mac OS X
Affected Version From: Mac OS X 10.9
Affected Version To: Mac OS X 10.10.3
Patch Exists: YES
Related CWE: CVE-2015-3673
CPE: o:apple:mac_os_x
Platforms Tested: OS X
2015
Apple OS X Entitlements Rootpipe Privilege Escalation
This module exploits the rootpipe vulnerability and bypasses Apple's initial fix for the issue by injecting code into a process with the 'admin.writeconfig' entitlement.
Mitigation:
Apply the latest security updates and patches from Apple.