Vulnerability Note VU#315856
Apple Mac OS X UserNotificationCenter privilege escalation vulnerability
Overview
Apple's UserNotificationCenter contains a vulnerability that may allow local users to gain elevated privileges.
Description
The Apple UserNotificationCenter contains a privilege escalation vulnerability. This vulnerability occurs because the Apple UserNotificationCenter runs with elevated privileges while operating on input submitted by users with normal privileges. |
Impact
A user with valid login credentials may be able to run commands or modify system files with elevated privileges. |
Solution
Apply an update |
Systems Affected (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Apple Computer, Inc. | Affected | - | 16 Feb 2007 |
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | N/A | N/A |
Temporal | N/A | N/A |
Environmental | N/A | N/A |
References
- http://docs.info.apple.com/article.html?artnum=305102
- http://developer.apple.com/documentation/CoreFoundation/Reference/CFUserNotificationRef/Reference/reference.html
- http://projects.info-pull.com/moab/MOAB-22-01-2007.html
- http://www.cocoadev.com/index.pl?InputManager
- http://secunia.com/advisories/23846/
- http://www.securityfocus.com/bid/22188
- http://secunia.com/advisories/24198/
Credit
LMH published this vulnerability on the Month of Apple Bugs website.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: CVE-2007-0023
- Date Public: 23 Jan 2007
- Date First Published: 19 Feb 2007
- Date Last Updated: 19 Feb 2007
- Severity Metric: 1.49
- Document Revision: 23
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.