5.1
CVSSv2

CVE-2017-7004

Published: 03/04/2018 Updated: 04/05/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in certain Apple products. iOS prior to 10.3.2 is affected. macOS prior to 10.12.5 is affected. The issue involves the "Security" component. A race condition allows malicious users to bypass intended entitlement restrictions for sending XPC messages via a crafted app.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple iphone os

Exploits

/* Source: bugschromiumorg/p/project-zero/issues/detail?id=1223 One way processes in userspace that offer mach services check whether they should perform an action on behalf of a client from which they have received a message is by checking whether the sender possesses a certain entitlement These decisions are made using the audit toke ...