Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: dayglored
Requires Administrative access, and THEN it "allows user privilege escalation"... you don't need an additional vuln. What am I not understanding here?

If you already have Admin access, you can do anything you want on the computer including give other normal users admin privilege.

What you're missing is that on a Mac, the Administrator account is not the highest level access. While I t's still limited, requiring name and password to do things and some things are still prohibited, the ROOT user is above Administrator level.

This vulnerability allows an admin to escalate his privileges by being able to open and write to ROOT-access-only files with impunity, regardless of what permissions are set on those files. That includes the files establishing who has access to what files, including ROOT files and who is a ROOT user! Privilege escalation from Admin to ROOT! Of course, on a Mac, the original Admin can create the first ROOT user and establish the ROOT password, so again, for most Mac users, this vulnerability is moot, because they could already do what it gives them the ability to do.

For some very limited number of Macs (I have trouble thinking of any, but it's possible) where an owner, who is the only one who knows the ROOT user name and password, has given admin privileges to one or two admins and some other users have only standard privileges, it might be a threat if one of the admins is too trustworthy. The it's an Oops!

7 posted on 07/22/2015 11:59:54 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 3 | View Replies ]


To: Swordmaker
Oh, I knew that root is above administrative users (and that there is no user called Administrator unless you feel like making one). I think of it like this: What I meant by "What am I not understanding here?" was more like... "What's the big deal, because anyone with admin access can sudo already."
23 posted on 07/23/2015 10:09:22 PM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 7 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson