9.3
CVSSv2

CVE-2015-5784

Published: 17/08/2015 Updated: 21/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

runner in Install.framework in the Install Framework Legacy component in Apple OS X prior to 10.10.5 does not properly drop privileges, which allows malicious users to execute arbitrary code in a privileged context via a crafted app.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=477 Installframework has a suid root binary here: /System/Library/PrivateFrameworks/Installframework/Resources/runner This binary vends the IFInstallRunner Distributed Object, which has the following method: [IFInstallRunner makeReceiptDirAt:asRoot:] If you pass ...