PT-2001-1337 · Apple · Macos 9

Publicado

2001-02-02

·

Atualizado

2021-09-22

·

CVE-2001-0102

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mac OS 9
Description: The issue allows normal users to gain owner privileges by removing the Users & Groups Data File, effectively removing the owner password. This enables a normal user to log in as the owner account without a password.
Recommendations: For Mac OS 9, consider implementing access controls to prevent normal users from removing the Users & Groups Data File as a temporary workaround. Restrict access to the Users & Groups Data File to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0102

Produtos afetados

Macos 9