CVE-2014-1264: Low severity Apple iOS and macOS vulnerability
Finder in Apple OS X before 10.9.2 does not ensure ACL integrity after the viewing of file ACL information, which allows local users to bypass intended access restrictions in opportunistic circumstances via standard filesystem operations on a file with a damaged ACL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple OS X Finderto a version that resolves this vulnerability.Fixed in 10.9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1264?
CVE-2014-1264 has a severity rating that indicates it allows local users to bypass intended access restrictions.
How do I fix CVE-2014-1264?
To fix CVE-2014-1264, it is recommended to upgrade to OS X version 10.9.2 or later.
Who is affected by CVE-2014-1264?
CVE-2014-1264 affects users of Apple OS X versions prior to 10.9.2.
What kind of vulnerability is CVE-2014-1264?
CVE-2014-1264 is a file permission vulnerability that affects ACL integrity.
Can CVE-2014-1264 be exploited remotely?
CVE-2014-1264 is a local vulnerability and cannot be exploited remotely.