409
VMScore

CVE-2020-9854

Published: 22/10/2020 Updated: 09/01/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5. An application may be able to gain elevated privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple iphone os

apple tvos

apple ipados

Github Repositories

A local privilege escalation chain from user to kernel for MacOS < 10.15.5. CVE-2020–9854

Unauthd (CVE-2020–9854) A local privilege escalation chain from user to kernel for MacOS &lt; 10155 How does it work? I wrote a blogpost explaining the vulnerabilities and exploitation methods I used It can be found here How do I use it? Build and run the unauthd target in the included xcode project It will hijack the acfskext print a message to the kernel log