Skip to content
COOEY

EXPOSURES › CVE-2015-1130

CVE-2015-1130

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-02-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-1130 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

A local authentication bypass in Apple OS X before 10.10.3 allowed users to gain admin privileges without remote exploitation.

This vulnerability required local access to exploit, meaning it did not enable remote code execution or compromise systems over the network. DIB organizations should care because it highlights the importance of patching known vulnerabilities promptly, as this CVE was listed in CISA's KEV catalog, indicating it was actively exploited in the wild. The failure stems from an unpatched flaw in the XPC implementation in Admin Framework, which could be leveraged by attackers with physical or local access to escalate privileges.

Shame score — The vulnerability was actively exploited in the wild and required patching, but it was not a zero-day or remote exploit, limiting its immediate catastrophic impact while still representing a significant avoidable risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.