Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html | patch vendor advisory |
http://www.securityfocus.com/bid/75493 | vdb entry |
http://www.securitytracker.com/id/1032760 | vdb entry |
https://www.exploit-db.com/exploits/38036/ | exploit |
http://support.apple.com/kb/HT204942 | vendor advisory |