First published: Tue Mar 30 2010(Updated: )
Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which allows remote authenticated users to leverage this former membership to obtain a server connection via screen sharing.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Server | =10.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-0522 is considered medium, as it allows unauthorized access to server features.
To fix CVE-2010-0522, you should update to a version of Mac OS X Server that includes security patches addressing this vulnerability.
CVE-2010-0522 affects users of Apple Mac OS X Server version 10.5.8, particularly those with former admin group memberships.
The impact of CVE-2010-0522 is that remote authenticated users can exploit previous admin privileges to gain unauthorized access via screen sharing.
As a workaround for CVE-2010-0522, review and revoke former admin privileges for users who no longer require them.