vendor:
macOS
by:
Csaba Fitzl
7.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: macOS
Affected Version From: macOS < 10.15.1
Affected Version To: macOS < 10.15.1
Patch Exists: YES
Related CWE: CVE-2019-8802
CPE: o:apple:mac_os_x
Other Scripts:
N/A
Platforms Tested: macOS
2020
MacOS 320.whatis Script – Privilege Escalation
This exploit is a privilege escalation vulnerability in macOS versions < 10.15.1. It is possible to gain root access by creating a bogus man page, creating a symlink in /usr/local/share/man/, creating a script file to be called by LaunchDaemon, and creating a python script to be called by the LaunchDaemon.
Mitigation:
Users should update their macOS version to 10.15.1 or later.