PT-2018-9868 · Objective See · Lulu+4
Josh Pitts
·
Published
2018-06-13
·
Updated
2019-10-03
·
CVE-2018-10404
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Objective-See KnockKnock (affected versions not specified)
Objective-See LuLu (affected versions not specified)
Objective-See TaskExplorer (affected versions not specified)
Objective-See WhatsYourSign (affected versions not specified)
Objective-See procInfo (affected versions not specified)
Description:
A maliciously crafted Universal/fat binary can evade third-party code signing checks, allowing unsigned code to execute. This occurs because the third-party tool does not complete a full inspection of the Universal/fat binary, leading the user to believe the code is signed by Apple.
Recommendations:
For Objective-See KnockKnock, consider implementing full inspection of Universal/fat binaries to prevent evasion of code signing checks.
For Objective-See LuLu, consider implementing full inspection of Universal/fat binaries to prevent evasion of code signing checks.
For Objective-See TaskExplorer, consider implementing full inspection of Universal/fat binaries to prevent evasion of code signing checks.
For Objective-See WhatsYourSign, consider implementing full inspection of Universal/fat binaries to prevent evasion of code signing checks.
For Objective-See procInfo, consider implementing full inspection of Universal/fat binaries to prevent evasion of code signing checks.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Knock Knock
Lulu
Taskexplorer
Whatsyoursign
Procinfo