6.8
CVSSv2

CVE-2019-8561

Published: 18/12/2019 Updated: 20/12/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A malicious application may be able to elevate privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

Github Repositories

Proof of concept exploit for CVE-2019-8561 discovered by @jbradley89

CVE-2019-8561 Proof of concept exploit for CVE-2019-8561 discovered by Jaron Bradley (@jbradley89) (Patched in macOS 10144) This script exploits a TOCTOU bug in installer which enables code execution as root See Jaron's Objective By the Sea v2 talk "Bad Things in Small Packages" where he demonstrates getting r00t and bypassing SIP (NB All scripts other tha