vendor:
Mac OS X
by:
Emil Kvarnhammar
7.8
CVSS
HIGH
rootpipe
264
CWE
Product Name: Mac OS X
Affected Version From: 10.7.2005
Affected Version To: 10.10.2002
Patch Exists: YES
Related CWE: CVE-2015-1130
CPE: o:apple:mac_os_x:10.7.5
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/osx/local/rootpipe, https://www.infosecmatter.com/nessus-plugin-library/?id=84488, https://www.infosecmatter.com/nessus-plugin-library/?id=84489, https://www.infosecmatter.com/nessus-plugin-library/?id=118525, https://www.infosecmatter.com/nessus-plugin-library/?id=124990, https://www.infosecmatter.com/nessus-plugin-library/?id=110645, https://www.infosecmatter.com/nessus-plugin-library/?id=118990, https://www.infosecmatter.com/nessus-plugin-library/?id=111144, https://www.infosecmatter.com/nessus-plugin-library/?id=119187, https://www.infosecmatter.com/nessus-plugin-library/?id=110701
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OS X 10.7.5, 10.8.2, 10.9.5 and 10.10.2
2015
PoC exploit code for rootpipe (CVE-2015-1130)
This PoC exploit code is created by Emil Kvarnhammar, TrueSec for the rootpipe vulnerability (CVE-2015-1130). It is tested on OS X 10.7.5, 10.8.2, 10.9.5 and 10.10.2. It uses ctypes, objc, sys, Cocoa, and Foundation libraries to write a file with the given source binary to the given destination binary as root.
Mitigation:
Apple has released a security update to address this vulnerability.