Security bypass vulnerability in Admin Framework in Apple OS X - CVE-2015-3673ID: oval:org.secpod.oval:def:25279 | Date: (C)2015-07-07 (M)2024-02-19 |
Class: VULNERABILITY | Family: macos |
The host is installed with Apple Mac OS X or Server 10.10.x through 10.10.3 and is prone to a security bypass vulnerability. A flaw is present in the application, which does not properly restrict the location of writeconfig clients. Successful exploitation allows attackers to obtain root privileges by moving and then modifying Directory Utility.
Platform: |
Apple Mac OS X 10.10 |
Apple Mac OS X Server 10.10 |