CVE-2015-1130
KEVmassLocal Authentication Bypass in Apple OS X Admin Framework (XPC)
CISA: Apple OS X Authentication Bypass Vulnerability
CVE-2015-1130 is a flaw in the XPC implementation of the Admin Framework in Apple OS X, where the framework fails to properly enforce authentication for administrative actions. A local user can trigger the vulnerable XPC service with a crafted request, bypassing the authentication check. Successful exploitation grants the attacker admin (root-level) privileges on the machine, enabling full local privilege escalation from an ordinary user account. Any Mac running OS X before 10.10.3 is affected, making this relevant to shared or multi-user Macs where attackers only need a low-privileged foothold. The flaw was patched by Apple in OS X 10.10.3, but CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, indicating confirmed exploitation in the wild; EPSS assigns it a 9.9% probability of exploitation in the next 30 days (95th percentile).
What to do: Upgrade affected Macs to OS X 10.10.3 or later, per Apple's vendor instructions, as required by the CISA KEV listing. Since this is a local privilege escalation, prioritize shared, multi-user, and managed Macs where attackers are more likely to have a low-privileged foothold, and verify via endpoint inventory that no systems remain on pre-10.10.3 builds.
| Apple OS X | all versions prior to 10.10.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.
- Affected
- Apple OS X
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Apple
- Products
- OS X
- Weakness
- CWE-254