First published: Thu Oct 28 2004(Updated: )
Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switching.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Remote Desktop | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0962 is considered a critical vulnerability due to its potential to allow remote authenticated users to execute arbitrary code as root.
To mitigate CVE-2004-0962, users should update Apple Remote Desktop to the latest version provided by Apple.
CVE-2004-0962 affects users of Apple Remote Desktop Client 1.2.4 when used in conjunction with Apple Remote Desktop Administrator application.
CVE-2004-0962 allows remote authenticated users to execute arbitrary code within the affected system while loginwindow is active.
CVE-2004-0962 specifically affects Apple Remote Desktop version 2.0.0, which may be tied to certain Mac OS versions corresponding with its release.