VulnerabilityModified
CVE-2018-4251
It allows attackers to modify the EFI flash-memory region that a crafted app that has root access.
MEDIUM 5.5EPSS 1.23%
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" component. It allows attackers to modify the EFI flash-memory region that a crafted app that has root access.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- apple/mac os x
- Source
- product-security@apple.com
References
- http://seclists.org/fulldisclosure/2019/Mar/45Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1041027Third Party Advisory, VDB Entry
- https://support.apple.com/HT208849Vendor Advisory
- http://seclists.org/fulldisclosure/2019/Mar/45Mailing List, Third Party Advisory
- http://www.securitytracker.com/id/1041027Third Party Advisory, VDB Entry
- https://support.apple.com/HT208849Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.