7.2
CVSSv2

CVE-2007-0752

Published: 24/05/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.4.8

apple mac os x server 10.4.8

Exploits

Mac OS X <= 1048 pppd Plugin Loading Privilege Escalation Exploit githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/3985tar (05252007-osxpppdtar) # milw0rmcom [2007-05-25] ...