Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-4887

Опубликовано: 19 сент. 2006
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote Desktop itself, but in applications that are installed while using it.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apple:apple_remote_desktop:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:apple_remote_desktop:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:apple_remote_desktop:3.0.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
Версия до 10.2.8 (включая)

EPSS

Процентиль: 21%
0.00068
Низкий

7.2 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote Desktop itself, but in applications that are installed while using it.

EPSS

Процентиль: 21%
0.00068
Низкий

7.2 High

CVSS2

Дефекты

NVD-CWE-Other