vendor:
iPhoto
by:
Kevin Finisterre
7.5
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: iPhoto
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:apple:iphoto
Platforms Tested: macOS
2007
Proof of Concept for MOAB-04-01-2007
This is a proof of concept exploit for the MOAB-04-01-2007 vulnerability. It targets iPhoto, a photo management application on macOS. The exploit takes advantage of a buffer overflow vulnerability in iPhoto's handling of XML feeds, allowing an attacker to execute arbitrary code on a target system. By sending a specially crafted XML feed, an attacker can trigger the buffer overflow and gain control over the target system.
Mitigation:
The vendor has released a patch for this vulnerability. It is recommended to update to the latest version of iPhoto to mitigate the risk of exploitation.