Zero-day vulnerability in macOS

Improper file permissions handling
CVE-2007-0117

Not patched

Vulnerability details

Advisory: SB2007010601 - Privilege escalation in Mac OS X

Vulnerable component: macOS

CVE-ID: CVE-2007-0117

CVSSv3 score: CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:F/RL:U/RC:C

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Description:

The vulnerability allows a local user to escalation privileges on vulnerable system.

The vulnerability exists in diskutil tool within DiskManagement framework when handling BOM files. A local user can create a specially crafted BOM file, run diskutil with specially crafted BOM file and replace permissions for arbitrary files on vulnerable system.

Successful exploitation of this vulnerability allows a local unprivileged user to elevate his privileges and gain root access to vulnerable system.

Note: the vulnerability is being actively exploited.

Public Exploits: