CVE-2018-10404: High severity verbb knock knock vulnerability
An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10404?
CVE-2018-10404 is classified as a high severity vulnerability due to the potential for malicious Universal/fat binaries to evade security checks.
How do I fix CVE-2018-10404?
To fix CVE-2018-10404, ensure that you are using the latest versions of affected software such as Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo.
Which software is affected by CVE-2018-10404?
CVE-2018-10404 affects Objective-See KnockKnock versions up to 1.9.3, LuLu up to 0.9.8, TaskExplorer up to 1.6.0, WhatsYourSign up to 1.4.0, and procInfo.
What type of vulnerability is CVE-2018-10404?
CVE-2018-10404 is a code signing vulnerability that allows bypassing third-party code signing checks on certain software.
How can CVE-2018-10404 impact my system?
CVE-2018-10404 can lead to the execution of unverified malicious code, potentially compromising system security.