First published: Wed Nov 29 2017(Updated: )
Directory Utility. A logic error existed in the validation of credentials. This was addressed with improved credential validation.
Credit: CVE-2017-13872 product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS High Sierra | <10.13.2 | 10.13.2 |
Apple Sierra | ||
Apple El Capitan | ||
Apple Mac OS X | =10.13.0 | |
Apple Mac OS X | =10.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-13872 is a vulnerability in macOS High Sierra where a logic error in the validation of credentials allows attackers to obtain administrator access without a password.
macOS High Sierra versions before Security Update 2017-001 are affected by CVE-2017-13872.
Attackers can exploit CVE-2017-13872 by performing certain interactions involving the entry of the root username.
CVE-2017-13872 has a severity rating of critical with a CVSS score of 8.1.
To fix CVE-2017-13872, update macOS High Sierra to Security Update 2017-001 or a later version.