Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and...
Vulnerability Description
Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote Desktop itself, but in applications that are installed while using it.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4887
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/20092
- http://www.securityfocus.com/archive/1/446371/100/0/threaded
- http://www.securityfocus.com/archive/1/446751/100/0/threaded
- http://www.securityfocus.com/archive/1/447043/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29060
- http://www.osvdb.org/32260
More from apple
View All →Affected Vendor
apple
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.