CVE-2017-7149
It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x
- Source
- product-security@apple.com
References
- http://www.securityfocus.com/bid/101178Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039513Third Party Advisory, VDB Entry
- https://hackernoon.com/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79Exploit, Third Party Advisory
- https://nakedsecurity.sophos.com/2017/10/05/urgent-update-your-mac-again-right-now/Exploit, Technical Description, Third Party Advisory
- https://support.apple.com/HT208165Vendor Advisory
- https://www.theregister.co.uk/2017/10/05/apple_patches_password_hint_bug_that_revealed_password/Exploit, Press/Media Coverage, Third Party Advisory
- http://www.securityfocus.com/bid/101178Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039513Third Party Advisory, VDB Entry
- https://hackernoon.com/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79Exploit, Third Party Advisory
- https://nakedsecurity.sophos.com/2017/10/05/urgent-update-your-mac-again-right-now/Exploit, Technical Description, Third Party Advisory
- https://support.apple.com/HT208165Vendor Advisory
- https://www.theregister.co.uk/2017/10/05/apple_patches_password_hint_bug_that_revealed_password/Exploit, Press/Media Coverage, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.