First published: Tue Oct 26 1999(Updated: )
Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS | =9 | |
=9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1076 has a medium severity rating due to its potential to allow local users to bypass idle session protections.
To fix CVE-1999-1076, ensure that the MacOS 9 system applies all available security updates and patches.
Local users of Apple macOS 9 are affected by CVE-1999-1076 due to the idle locking bypass vulnerability.
CVE-1999-1076 is classified as a local security vulnerability that allows unauthorized access to locked sessions.
No, CVE-1999-1076 cannot be exploited remotely as it requires local access to the affected MacOS 9 system.