CVE-2007-3749
The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thread Exception Port when executing a setuid program, which allows local users to execute arbitrary code by creating the port before launching the setuid…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thread Exception Port when executing a setuid program, which allows local users to execute arbitrary code by creating the port before launching the setuid program, then writing to the address space of the setuid process.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-665
- Affected
- apple/mac os x
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=307041Broken Link
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=630Broken Link
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.htmlMailing List
- http://secunia.com/advisories/27643Broken Link, Vendor Advisory
- http://www.securityfocus.com/bid/26444Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-319A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/3868Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38466Third Party Advisory, VDB Entry
- http://docs.info.apple.com/article.html?artnum=307041Broken Link
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=630Broken Link
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.htmlMailing List
- http://secunia.com/advisories/27643Broken Link, Vendor Advisory
- http://www.securityfocus.com/bid/26444Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-319A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/3868Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38466Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.