7.8
CVSSv3

CVE-2018-4237

Published: 08/06/2018 Updated: 03/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in certain Apple products. iOS prior to 11.4 is affected. macOS prior to 10.13.5 is affected. tvOS prior to 11.4 is affected. watchOS prior to 4.3.1 is affected. The issue involves the "libxpc" component. It allows malicious users to gain privileges via a crafted app that leverages a logic error.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple mac os x

apple watchos

apple tvos

Exploits

This Metasploit module exploits a vulnerability in libxpc on macOS versions 10133 and below The task_set_special_port API allows callers to overwrite their bootstrap port, which is used to communicate with launchd This port is inherited across forks: child processes will use the same bootstrap port as the parent By overwriting the bootstrap po ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2018-7-23-2 Additional information for APPLE-SA-2018-06-01-1 macOS High Sierra 10135, Security Update 2018-0 ...

Github Repositories

Introduction to macOS - Mach Ports In previous blogposts, we discussed several security mechanisms of macOS: We discussed how Entitlements effectively create another security layer We mentioned SIP and how it seperates the system from the root user We discussed the macOS App Sandbox and how it can enforce policies on processes We mentioned Gatekeeper and the Quarantine Exte