Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v10.5 - Exploits Update (Tue Nov 16 2010)

Mac OS X AppleScript ARDAgent Shell Local Privilege Escalation Exploit

Exploits/Local  [Mac OS X]




• Tue Nov 16 2010
The problem is that "ARDAgent", which is owned by "root" and has the setuid bit set, can be invoked to execute shell commands via AppleScript (e.g. through "osascript"). This can be exploited to execute arbitrary commands with root privileges.

Exploits Vulnerabiltiy: CVE-2008-2830



< Back to Product Updates