First published: Fri May 11 2012(Updated: )
Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is enabled, allows physically proximate attackers to login to arbitrary accounts by entering the account name and no password.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.7.0 | |
Apple iOS and macOS | =10.7.1 | |
Apple iOS and macOS | =10.7.2 | |
Apple iOS and macOS | =10.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0656 is rated as a high severity vulnerability due to the potential for unauthorized access to user accounts.
To fix CVE-2012-0656, you should update your system to Mac OS X 10.7.4 or later.
The vulnerability affects users of Apple Mac OS X 10.7.x before 10.7.4 with the Guest account enabled.
CVE-2012-0656 exploits a race condition in the LoginUIFramework, allowing attackers to log in without a password.
CVE-2012-0656 cannot be exploited remotely; it requires physical access to the device.