MacOS Process Code Signing: Invalid Apple

Critical Nessus Plugin ID 121031

Synopsis

Nessus found processes running on the host that appear to be Apple but are suspect.

Description

Running processes that appear to be Apple but are suspect.

See Also

http://www.nessus.org/u?51eff38a

http://www.nessus.org/u?b446c0fe

http://www.nessus.org/u?8e9d177b

Plugin Details

Severity: Critical

ID: 121031

File Name: macos_codesign_invalid_apple.nbin

Version: 1.8

Type: local

Agent: unix

Family: Backdoors

Published: 2019/01/09

Updated: 2019/08/20

Dependencies: 12634, 121034

Risk Information

Risk Factor: Critical

CVSS Score Source: manual

CVSS Score Rationale: The detection is suspected as being malware.

CVSS v2.0

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3.0

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

Required KB Items: Host/uname