Apple Remote Desktop contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when ARD is used to remotely execute an installation package, and a user is able to click on the desktop to access a Finder window with root access. This flaw may lead to a loss of integrity.
Classification
Location:
Local Access Required,
Remote / Network Access
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Public
Solution
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s):
Use the "Lock Desktop" feature of Apple Remote Desktop, which locks the user's desktop until administrative tasks have been completed.