CVE-2017-6974: Input Validation
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the "System Integrity Protection" component. It allows attackers to modify the contents of a protected disk location via a crafted app.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOS (System Integrity Protection)to a version that resolves this vulnerability.Fixed in 10.12.4
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6974?
CVE-2017-6974 has a high severity due to its ability to allow unauthorized modification of protected system files.
How do I fix CVE-2017-6974?
The recommended fix for CVE-2017-6974 is to update macOS to version 10.12.4 or later where the vulnerability is patched.
Which systems are affected by CVE-2017-6974?
CVE-2017-6974 affects macOS versions prior to 10.12.4, specifically 10.12.3.
What can attackers do exploiting CVE-2017-6974?
Exploiting CVE-2017-6974 allows attackers to modify the contents of protected disk locations through a crafted application.
Is System Integrity Protection related to CVE-2017-6974?
Yes, CVE-2017-6974 involves a vulnerability within the System Integrity Protection subsystem of macOS.