PT-2001-1337 · Apple · Macos 9
Publicado
2001-02-02
·
Atualizado
2021-09-22
·
CVE-2001-0102
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Mac OS 9
Description:
The issue allows normal users to gain owner privileges by removing the Users & Groups Data File, effectively removing the owner password. This enables a normal user to log in as the owner account without a password.
Recommendations:
For Mac OS 9, consider implementing access controls to prevent normal users from removing the Users & Groups Data File as a temporary workaround. Restrict access to the Users & Groups Data File to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Macos 9