vendor:
macOS
by:
phoenhex
7,8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: macOS
Affected Version From: macOS 10.12.5
Affected Version To: macOS 10.12.6
Patch Exists: YES
Related CWE: N/A
CPE: o:apple:mac_os_x:10.12.6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: macOS
2017
Diskarbitrationd Privilege Escalation
This exploit is a privilege escalation vulnerability in the Diskarbitrationd service of macOS. It allows an attacker to gain root privileges on the system by exploiting a race condition between the Diskarbitrationd service and the atrun service. The exploit involves mounting a malicious disk image, creating a symbolic link to the /private/var/at directory, and then creating a cron job that will execute a setuid root binary. The attacker can then execute the binary to gain root privileges.
Mitigation:
The vulnerability can be mitigated by disabling the atrun service or by applying the Apple security update.