CVE-2006-4413
Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Affected
- apple/remote desktop
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00000.html
- http://secunia.com/advisories/22982Vendor Advisory
- http://securitytracker.com/id?1017241
- http://www.securityfocus.com/bid/21139
- http://www.vupen.com/english/advisories/2006/4567
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00000.html
- http://secunia.com/advisories/22982Vendor Advisory
- http://securitytracker.com/id?1017241
- http://www.securityfocus.com/bid/21139
- http://www.vupen.com/english/advisories/2006/4567
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.