Security restrictions bypass in macOS - CVE-2018-4225

 

Security restrictions bypass in macOS - CVE-2018-4225

Published: June 4, 2018


Vulnerability identifier: #VU13173
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4225
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass security restrictions on the target system.

The vulnerability exists due to a state management error in the Security component. A local attacker can bypass security restrictions and modify the state of the Keychain.


Affected software

macOS
watchOS
Apple iOS
iCloud for Windows
iTunes
IBM Watson Explorer Deep Analytics Edition Analytical Components

How to mitigate CVE-2018-4225

Update to version 10.13.4.

IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.16

External References

Related Security Bulletins