PT-2015-3107 · Apple · Os X

Macdefender

·

Publicado

2015-12-11

·

Atualizado

2017-09-13

·

CVE-2015-7044

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple OS X versions prior to 10.11.2
Description The issue is related to errors in security settings of the System Integrity Protection feature. It may allow a remote attacker to execute arbitrary code in a privileged context using a specially crafted app with root privileges. The problem arises from the mishandling of union mounts.
Recommendations For Apple OS X versions prior to 10.11.2, update to version 10.11.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of apps with root privileges to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00317
CVE-2015-7044

Produtos afetados

Os X