Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html | patch vendor advisory |
http://www.securityfocus.com/bid/75493 | vdb entry |
http://www.securitytracker.com/id/1032760 | vdb entry |
http://support.apple.com/kb/HT204942 | vendor advisory |