First published: Fri Jul 03 2015(Updated: )
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3673 is considered a high-severity vulnerability due to its potential for local users to escalate privileges to root.
To fix CVE-2015-3673, update your Apple OS X to version 10.10.4 or later.
CVE-2015-3673 affects Apple OS X versions prior to 10.10.4, specifically up to 10.10.3.
The impact of CVE-2015-3673 allows local users to gain root privileges, which can lead to unauthorized system control.
There is no official workaround for CVE-2015-3673 besides upgrading to a secure version of OS X.