ID:3878 - Exploit for Data Handling in macOS - CVE-2014-8835

 
Main Vulnerability Database Exploits ID:3878 - Exploit for Data Handling in macOS - CVE-2014-8835

ID:3878 - Exploit for Data Handling in macOS - CVE-2014-8835

Published: August 9, 2020


Vulnerability identifier: #VU40921
Vulnerability risk: High
CVE-ID: CVE-2014-8835
CWE-ID: CWE-19
Exploitation vector: Remote access
Vulnerable software:
macOS

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type, which allows attackers to execute arbitrary code by providing a crafted dictionary to sysmond, related to an "XPC type confusion" issue.


Remediation

Install update from vendor's website.