First published: Mon Nov 01 1999(Updated: )
Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS | =9 | |
=9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1077 is considered a moderate severity vulnerability affecting MacOS 9.
To fix CVE-1999-1077, users should avoid using the idle function or ensure that unattended sessions are monitored closely.
CVE-1999-1077 affects any local user of MacOS 9 who has access to a computer with an idled and password-protected session.
CVE-1999-1077 enables local attackers to bypass session locks and access sensitive information.
A potential workaround for CVE-1999-1077 is to manually lock the screen when stepping away from the computer.