Exploit Apple Mac OSX 10.1.x - SoftwareUpdate Arbitrary Package Installation

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21596
Проверка EDB
  1. Пройдено
Автор
RUSSELL HARDING
Тип уязвимости
REMOTE
Платформа
OSX
CVE
cve-2002-0676
Дата публикации
2002-07-08
Код:
source: https://www.securityfocus.com/bid/5176/info

A vulnerability has been reported for MacOS X where an attacker may use SoftwareUpdate to install malicious software on the vulnerable system. SoftwareUpdate uses HTTP, without any authentication, to obtain updates from Apple. Any updated packages are installed on the system as the root user.

In order to exploit this vulnerability, the attacker must control the machine located at swquery.apple.com, from the perspective of the vulnerable client. It may be possible to create this condition through some known techniques, including DNS cache poisoning and DNS spoofing.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/21596.tgz.tar
 
Источник
www.exploit-db.com

Похожие темы