CVE-1999-1077: Medium severity macOS vulnerability
Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the ability for the programmer's switch or the CMD-PWR keyboard sequence to invoke a debugger so the debugger cannot be used to disable the idle session lock.
macOS 9 debugger invocation via programmer's switch / CMD-PWR = disabled - Compensating control
Restrict physical/local access to affected machines (for example, lock server/console rooms, limit console access to trusted personnel) to prevent local attackers from using the programmer's switch or keyboard sequences to bypass idle locks.
- Operational
Require users to fully log out or shut down before leaving a workstation unattended rather than relying solely on the idle-lock feature; instruct users and administrators about this limitation of idle locking on macOS 9.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1077?
CVE-1999-1077 is considered a moderate severity vulnerability affecting MacOS 9.
How do I fix CVE-1999-1077?
To fix CVE-1999-1077, users should avoid using the idle function or ensure that unattended sessions are monitored closely.
Who is affected by CVE-1999-1077?
CVE-1999-1077 affects any local user of MacOS 9 who has access to a computer with an idled and password-protected session.
What type of attack does CVE-1999-1077 enable?
CVE-1999-1077 enables local attackers to bypass session locks and access sensitive information.
Is there a workaround for CVE-1999-1077?
A potential workaround for CVE-1999-1077 is to manually lock the screen when stepping away from the computer.