A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan. An attacker with physical access to a device may be able to elevate privileges.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mac_os_x | Apple | * | 10.13.5 (excluding) |
| Mac_os_x | Apple | 10.11 (including) | 10.11.6 (excluding) |
| Mac_os_x | Apple | 10.12 (including) | 10.12.6 (excluding) |
| Mac_os_x | Apple | 10.11.6 (including) | 10.11.6 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2016-001 (including) | 10.11.6-security_update_2016-001 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2016-002 (including) | 10.11.6-security_update_2016-002 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2016-003 (including) | 10.11.6-security_update_2016-003 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2017-001 (including) | 10.11.6-security_update_2017-001 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2017-002 (including) | 10.11.6-security_update_2017-002 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2017-003 (including) | 10.11.6-security_update_2017-003 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2017-004 (including) | 10.11.6-security_update_2017-004 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2017-005 (including) | 10.11.6-security_update_2017-005 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2018-001 (including) | 10.11.6-security_update_2018-001 (including) |
| Mac_os_x | Apple | 10.11.6-security_update_2018-002 (including) | 10.11.6-security_update_2018-002 (including) |
| Mac_os_x | Apple | 10.12.6 (including) | 10.12.6 (including) |
| Mac_os_x | Apple | 10.12.6-security_update_2017-001 (including) | 10.12.6-security_update_2017-001 (including) |
| Mac_os_x | Apple | 10.12.6-security_update_2017-002 (including) | 10.12.6-security_update_2017-002 (including) |
| Mac_os_x | Apple | 10.12.6-security_update_2018-001 (including) | 10.12.6-security_update_2018-001 (including) |
| Mac_os_x | Apple | 10.12.6-security_update_2018-002 (including) | 10.12.6-security_update_2018-002 (including) |