First published: Sun Apr 02 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7585 has a moderate severity level as it allows physically proximate attackers to uncover sensitive information.
To mitigate CVE-2016-7585, upgrade macOS to version 10.12.4 or later.
CVE-2016-7585 affects users of macOS versions prior to 10.12.4.
CVE-2016-7585 involves improper handling of direct memory access (DMA) in the EFI component.
Attackers can use CVE-2016-7585 to discover the FileVault 2 encryption password through a specially crafted Thunderbolt adapter.