First published: Sun Apr 02 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "sudo" component. It allows remote authenticated users to gain privileges by leveraging membership in the admin group on a network directory server.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2381 is classified as a moderate-severity vulnerability that allows remote authenticated users to gain elevated privileges.
To fix CVE-2017-2381, update your macOS to version 10.12.4 or later.
CVE-2017-2381 affects users of macOS versions prior to 10.12.4.
CVE-2017-2381 exploits the 'sudo' component by allowing admin group members on a network directory server to gain unauthorized privileges.
There are no known workarounds for CVE-2017-2381; the best action is to apply the necessary software update.