Risk
- Privilege Escalation
Affected Systems
- Mac OS X
Mac OS X versions 10.10.0 to 10.10.4
Summary
A vulnerability has been discovered in Apple Mac OS X. It allows an attacker to achieve privilege escalation.
Solution
Exploitation of this vulnerability is based on the overflow of an environment variable in Mac OS 10.10.x. Indeed, the implicated environment variable allows the system to indicate a file in which to log errors.
The exploitation of this vulnerability therefore allows arbitrary file writing with high privileges and can thus lead to privilege escalation.
This feature is only available from version 10.10 of Mac OS X, so earlier versions are not affected.
Refer to the vendor's security bulletin for obtaining patches (see Documentation section).
Documentation
- OS X 10.10 DYLD_PRINT_TO_FILE Local Privilege Escalation Vulnerability of December 22, 2015 /notice/CERTFR-2015-AVI-355/
- Vendor security bulletin https://support.apple.com/en-us/HT205031
- SUIDGuard kernel extension https://github.com/sektioneins/SUIDGuard
- OS X 10.10 DYLD_PRINT_TO_FILE Local Privilege Escalation Vulnerability https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_file_lpe.html
