First published: Sun Sep 25 2016(Updated: )
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4710 is considered a high-severity vulnerability that allows local users to escalate privileges to root.
To fix CVE-2016-4710, update to macOS version 10.12 or later where the vulnerability has been addressed.
CVE-2016-4710 affects local users on Apple OS X versions prior to 10.12.
CVE-2016-4710 is a privilege escalation vulnerability caused by type confusion in WindowServer.
CVE-2016-4710 requires local access to the affected system, so it cannot be exploited remotely.