Title: Cisco Trust Agent on Mac OS X User Notification Authentication Bypass
Info
Disclosure
Jun 11, 2007
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Trust Agent for Mac OS X contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the agent delivers a message to a login screen, or over the password prompt to exit the screensaver, through which an unauthenticated user can access System Preferences as the root user. This flaw may lead to a loss of integrity.
Classification
Location:
Local Access Required
Attack Type:
Other
Impact:
Loss of Integrity
Exploit:
Exploit Public
OSVDB:
Security Software
Solution
Upgrade to version 2.1.104.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.