First published: Mon Sep 25 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "DesktopServices" component. It allows local users to bypass intended access restrictions on home folder files.
Credit: product-security@apple.com Henrique Correa de Amorim
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | =10.13.0 | |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-13851 is a vulnerability that affects certain Apple products running macOS before 10.13.0.
CVE-2017-13851 allows local users to bypass intended access restrictions on home folder files.
CVE-2017-13851 has a severity rating of 5.5, which is considered medium.
macOS High Sierra version 10.13.0 is affected by CVE-2017-13851.
To fix CVE-2017-13851, update your macOS High Sierra to a version higher than 10.13.0.