|
Class: Design Error
Remote: Yes, through SSH
Local: Yes
Published: June 18 2008 6:15 PM CST
Credit: Anonymous post on Slashdot.org
Vulnerable: Apple Mac OS X 10.5.3
Code for OS X root escalation was in the wild today after an anonymous post on the tech-oriented site Slashdot.org (http://it.slashdot.org/article.pl?sid=08/06/18/1919224). Due to an insecurity in the root-owned Apple Remote Desktop Agent binary, local users, as well as those with SSH access while the local user was logged into the graphic user interface, can execute commands with root privileges via Applescript. This vulnerability exists under both admin and regular user accounts under the latest version of OS X (10.5.3), and works regardless of whether Apple Remote Desktop sharing is turned on. This vulnerability may exist in earlier versions of OS X.
This vulnerability could be exploited by tricking a user to download and open a file, or through the use of malicious installer scripts. Once executed, the exploit would have full control of the system.
SecureMac will update this advisory as more information becomes available.
FEEDBACK TIME!
|