Vulnerable component: MAC OS X
CVSSv3 score: CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:F/RL:U/RC:C
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
The vulnerability allows a local user to escalation privileges on vulnerable system.
The vulnerability exists in diskutil tool within DiskManagement framework when handling BOM files. A local user can create a specially crafted BOM file, run diskutil with specially crafted BOM file and replace permissions for arbitrary files on vulnerable system.
Successful exploitation of this vulnerability allows a local unprivileged user to elevate his privileges and gain root access to vulnerable system.
Note: the vulnerability is being actively exploited.