Vulnerability Name: | CVE-2008-2830 (CCN-43294) | ||||||||
Assigned: | 2008-06-18 | ||||||||
Published: | 2008-06-18 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 6.2 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
6.2 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-2830 Source: CCN Type: Slashdot Blog, Wednesday June 18, @04:39PM Mac OS X Root Escalation Through AppleScript Source: MISC Type: UNKNOWN http://it.slashdot.org/it/08/06/18/1919224.shtml Source: APPLE Type: UNKNOWN APPLE-SA-2008-09-16 Source: APPLE Type: UNKNOWN APPLE-SA-2008-07-31 Source: CCN Type: SA30776 Apple Mac OS X ARDAgent Privilege Escalation Vulnerability Source: SECUNIA Type: UNKNOWN 30776 Source: CCN Type: SECTRACK ID: 1020345 Mac OS X Apple Remote Desktop Agent Lets Local Users Gain Root Privileges Source: CCN Type: Apple Web site Apple - Mac OS X Source: CCN Type: OSVDB ID: 46490 Apple Mac OS X ARDAgent osascript tell Command Local Privilege Escalation Source: BID Type: Exploit 29831 Source: CCN Type: BID-29831 Apple Mac OS X AppleScript ARDAgent Shell Local Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1020345 Source: VUPEN Type: UNKNOWN ADV-2008-1905 Source: XF Type: UNKNOWN macosx-ardagent-command-execution(43294) Source: XF Type: UNKNOWN apple-macosx-ardagent-command-execution(43294) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |