First published: Sat Oct 18 2014(Updated: )
NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible, which allows remote attackers to read or write to files by leveraging a state in which File Sharing is permanently enabled.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4441 is considered a moderate severity vulnerability due to the risk of unauthorized file access.
To mitigate CVE-2014-4441, ensure that you upgrade your OS X to version 10.10 or later, where the vulnerability is resolved.
CVE-2014-4441 allows remote attackers to read or write files when File Sharing is permanently enabled without proper security controls.
CVE-2014-4441 affects OS X versions prior to 10.10, including all releases up to 10.9.5.
While upgrading is the best option, disabling File Sharing can serve as a temporary workaround to limit exposure for CVE-2014-4441.