OSVDB ID: 32260

Title: Apple Remote Desktop Application Installation Privilege Escalation

Info

Disclosure

Sep 18, 2006

Discovery

Unknown

Dates

Exploit

Sep 18, 2006

Solution

Unknown

Description

Apple Remote Desktop contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when ARD is used to remotely execute an installation package, and a user is able to click on the desktop to access a Finder window with root access. This flaw may lead to a loss of integrity.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Misconfiguration
Impact: Loss of Integrity
Exploit: Exploit Public

Solution

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s): Use the "Lock Desktop" feature of Apple Remote Desktop, which locks the user's desktop until administrative tasks have been completed.

Products

Apple Inc.

Remote Desktop

Unknown or Unspecified

References

Credit

  • - fribitchorganic.com -


Direct URL: http://osvdb.org/32260