VulnerabilityModified
CVE-2007-0724
The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
MEDIUM 6.9EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x · apple/mac os x server
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=305214
- http://docs.info.apple.com/article.html?artnum=305391
- http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/24479
- http://secunia.com/advisories/24966
- http://www.osvdb.org/34855
- http://www.securityfocus.com/bid/22948
- http://www.securitytracker.com/id?1017751
- http://www.securitytracker.com/id?1017942
- http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-109A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/0930
- http://www.vupen.com/english/advisories/2007/1470
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32973
- http://docs.info.apple.com/article.html?artnum=305214
- http://docs.info.apple.com/article.html?artnum=305391
- http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/24479
- http://secunia.com/advisories/24966
- http://www.osvdb.org/34855
- http://www.securityfocus.com/bid/22948
- http://www.securitytracker.com/id?1017751
- http://www.securitytracker.com/id?1017942
- http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-109A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/0930
- http://www.vupen.com/english/advisories/2007/1470
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32973
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.