4.3
CVSSv2

CVE-2020-27949

Published: 02/04/2021 Updated: 08/04/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may cause unexpected changes in memory belonging to processes traced by DTrace.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple mac os x 10.14.6

apple mac os x 10.15.7

apple macos

Github Repositories

Reading and writing memory of other processes using fasttrap The /dev/fasttrap device for creating trap nodes in user-space processes for the pid and objc providers has the permissions 666 In contrast to /dev/dtrace, which is also 666, fasttrap lacks a permission check This allows any process to issue a FASTTRAPIOC_MAKEPROBE or FASTTRAPIOC_GETINSTR ioctl An attacker can crea