First published: Tue Sep 19 2006(Updated: )
Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote Desktop itself, but in applications that are installed while using it.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Remote Desktop | =3.0.0 | |
Apple Remote Desktop | =2.0.0 | |
Apple Remote Desktop | =2.1.0 | |
macOS Yosemite | <=10.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4887 is classified as a moderate severity vulnerability due to its ability to allow local users to bypass authentication.
To fix CVE-2006-4887, update your Apple Remote Desktop to the latest version that addresses this privilege escalation issue.
CVE-2006-4887 affects users of Apple Remote Desktop versions 2.0.0, 2.1.0, and 3.0.0 on Mac OS X 10.2.8 and later.
The consequences of CVE-2006-4887 include unauthorized privilege escalation by local users when certain applications are installed.
CVE-2006-4887 is primarily a client-side vulnerability affecting the installation process on the remote machine.