vendor:
by:
Kevin Finisterre and Lance M. Havok
N/A
CVSS
N/A
Privilege Escalation
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Mac OS X
2007
Exploit for MOAB-21-01-2007: OS X, making root shells easier each day
This exploit allows an attacker to escalate privileges on a Mac OS X system, gaining root access. It uses a shell wrapper and shell planting technique to create and execute a malicious binary file. The exploit takes advantage of a vulnerability in the System Preferences application.
Mitigation:
Apply the necessary security updates and patches released by the vendor.