First published: Fri Jul 03 2015(Updated: )
Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3671 has a high severity rating due to its potential to allow local users to gain unauthorized admin privileges.
To fix CVE-2015-3671, users should update their Apple OS X to version 10.10.4 or later.
CVE-2015-3671 affects all versions of Apple OS X prior to 10.10.4, specifically those up to and including 10.10.3.
CVE-2015-3671 allows local users to bypass authentication mechanisms and potentially obtain admin privileges.
There is no specific workaround for CVE-2015-3671; the recommended action is to upgrade to a patched version of OS X.