Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2016/May/msg00006.html | vendor advisory |
http://www.securitytracker.com/id/1035887 | vdb entry |
https://support.apple.com/HT206379 | vendor advisory |