PT-2004-1980 · Apple · Loginwindow+1

Published

2004-10-28

·

Updated

2018-10-30

·

CVE-2004-0962

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apple Remote Desktop Client version 1.2.4
Description: The issue allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switching, because the Apple Remote Desktop Client executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application.
Recommendations: For Apple Remote Desktop Client version 1.2.4, consider restricting access to the application until a patch is available, and avoid using Fast User Switching when the loginwindow is active to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0962

Affected Products

Remote Desktop Client
Loginwindow