Mac OS X < 10.10.4 Multiple Vulnerabilities

critical Nessus Network Monitor Plugin ID 8801

Synopsis

The remote host is missing a critical Mac OS X patch update.

Description

The remote host is running a version of Mac OS X 10.10.x that is prior to version 10.10.4 and the following components contain vulnerabilities :

- Admin Framework
- afpserver
- apache
- AppleFSCompression
- AppleGraphicsControl
- AppleThunderboltEDMService
- ATS
- Bluetooth
- Certificate Trust Policy
- CFNetwork HTTPAuthentication
- CoreText
- coreTLS
- DiskImages
- Display Drivers
- EFI
- FontParser
- Graphics Driver
- ImageIO
- Install Framework Legacy
- Intel Graphics Driver
- IOAcceleratorFamily
- IOFireWireFamily
- Kernel
- kext tools
- Mail
- ntfs
- ntp
- OpenSSL
- QuickTime
- Security
- Spotlight
- SQLite
- System Stats
- TrueTypeScaler
- zip

Solution

Upgrade to Mac OS X 10.10.4 or later.

See Also

https://support.apple.com/en-ca/HT204942

Plugin Details

Severity: Critical

ID: 8801

Published: 10/12/2015

Updated: 3/6/2019

Nessus ID: 84488

Risk Information

VPR

Risk Factor: Critical

Score: 9.8

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Patch Publication Date: 1/26/2015

Vulnerability Publication Date: 1/7/2015

Exploitable With

CANVAS (CANVAS)

Metasploit (Apple OS X Entitlements Rootpipe Privilege Escalation)

Reference Information

CVE: CVE-2013-1741, CVE-2014-8127, CVE-2014-8128, CVE-2014-8129, CVE-2014-8130, CVE-2014-8139, CVE-2014-8140, CVE-2014-8141, CVE-2015-0209, CVE-2015-0235, CVE-2015-0273, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0293, CVE-2015-1157, CVE-2015-1798, CVE-2015-1799, CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, CVE-2015-3668, CVE-2015-3671, CVE-2015-3672, CVE-2015-3673, CVE-2015-3674, CVE-2015-3675, CVE-2015-3676, CVE-2015-3677, CVE-2015-3678, CVE-2015-3679, CVE-2015-3680, CVE-2015-3681, CVE-2015-3682, CVE-2015-3683, CVE-2015-3684, CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, CVE-2015-3688, CVE-2015-3689, CVE-2015-3690, CVE-2015-3691, CVE-2015-3692, CVE-2015-3693, CVE-2015-3694, CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, CVE-2015-3701, CVE-2015-3702, CVE-2015-3703, CVE-2015-3704, CVE-2015-3705, CVE-2015-3706, CVE-2015-3707, CVE-2015-3708, CVE-2015-3709, CVE-2015-3710, CVE-2015-3711, CVE-2015-3712, CVE-2015-3713, CVE-2015-3714, CVE-2015-3715, CVE-2015-3716, CVE-2015-3717, CVE-2015-3718, CVE-2015-3719, CVE-2015-3720, CVE-2015-3721, CVE-2015-4000

BID: 72326, 74733, 73225, 73227, 73231, 73232, 73237, 73239, 73950, 73951, 72323, 72352, 72353, 72701, 72325, 63736, 71790, 71792, 71793, 75493, 75491