vendor:
Mac OS X
by:
fG!
7
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Mac OS X
Affected Version From: Mavericks 10.10.5
Affected Version To: El Capitan 10.11.3
Patch Exists: YES
Related CWE: CVE-2016-1757
CPE: o:apple:mac_os_x
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mavericks 10.10.5, Yosemite 10.10.5, El Capitan 10.11.2 and 10.11.3
2015, 2016
Mach Race OS X Local Privilege Escalation Exploit
Mach Race OS X Local Privilege Escalation Exploit is a SUID, SIP, and binary entitlements universal OS X exploit (CVE-2016-1757). It is used to exploit a race condition in the Mach bootstrap subsystem. The exploit works by creating a Mach service with a predictable name and then racing against the kernel to register a receive right for that service. The exploit is used against a SUID binary or an entitled binary to bypass SIP. It is tested against Mavericks 10.10.5, Yosemite 10.10.5, El Capitan 10.11.2 and 10.11.3 and is fixed in El Capitan 10.11.4. It should work with all OS X versions.
Mitigation:
Upgrade to El Capitan 10.11.4 or later.