1. Research - Home |
  2. Advisories |
  3. Alerts |
  4. Tools |
  5. Papers |
  6. Services |
  7. Contact |
  8. About
Home > Alerts
Alerts
Alerts | Zero-Day Tracker | EEYEZD-20080618

Common Name:
Mac OS X ARDAgent Local Privilege Escalation

Date Disclosed:
6/18/2008

Expected Patch Release:
Unknown

Vendor:
Apply

Application:
OS X 10.5
OS X 10.4
Potentially Earlier Versions

Description:
ARDAgent in Apple Mac OS X 10.5 and 10.4 allows local users to gain privileges via an osascript tell command. This vulnerability is actively being exploited by attackers to install a trojan on a target system.

Severity:
High

Code Execution:
Yes (Local Privilege Escalation)

Impact:
Simple Elevation of Privileges
This vulnerability allows an attacker to very simply elevate the privileges of a process to root. This allows for the full subversion of a system, potentially resulting in a persistant trojan or other malicious binary to be installed with system-level privileges.

Mitigation:
Users are urged to only open known-sender AppleScript's or application bundles.

Protection:
Links:
First Public Disclosure
CVE-2008-2830
SecureMac: AppleScript.THT Trojan Horse Advisory
MacShadows: ARDAgent Exploit Wiki

Status:
6/18/2008 In-The-Wild Exploitation Witnessed