ZeroHour

CVE-2015-1130

KEVmass

Local Authentication Bypass in Apple OS X Admin Framework (XPC)

CISA: Apple OS X Authentication Bypass Vulnerability

CVSS
EPSS
10%p95
Published
KEV added
AI analysis

CVE-2015-1130 is a flaw in the XPC implementation of the Admin Framework in Apple OS X, where the framework fails to properly enforce authentication for administrative actions. A local user can trigger the vulnerable XPC service with a crafted request, bypassing the authentication check. Successful exploitation grants the attacker admin (root-level) privileges on the machine, enabling full local privilege escalation from an ordinary user account. Any Mac running OS X before 10.10.3 is affected, making this relevant to shared or multi-user Macs where attackers only need a low-privileged foothold. The flaw was patched by Apple in OS X 10.10.3, but CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, indicating confirmed exploitation in the wild; EPSS assigns it a 9.9% probability of exploitation in the next 30 days (95th percentile).

What to do: Upgrade affected Macs to OS X 10.10.3 or later, per Apple's vendor instructions, as required by the CISA KEV listing. Since this is a local privilege escalation, prioritize shared, multi-user, and managed Macs where attackers are more likely to have a low-privileged foothold, and verify via endpoint inventory that no systems remain on pre-10.10.3 builds.

Affected
Apple OS Xall versions prior to 10.10.3
Estimated exposure
masstens of millions of Macs ran affected OS X releases at the time of disclosure (Yosemite-era install base) — OS X Yosemite-era builds before 10.10.3 were among the most widely deployed Mac operating systems in 2015, with Apple's installed base in the tens of millions, so the cumulative affected population is on the order of tens of millions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.

CISA Known Exploited Vulnerability
Affected
Apple OS X
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Apple
Products
OS X
Weakness
CWE-254

In the news