EXPOSURES › CVE-2015-1130
CVE-2015-1130
HIGH ⌖ ON CISA KEV · EXPLOITEDA local authentication bypass in Apple OS X before 10.10.3 allowed users to gain admin privileges without remote exploitation.
This vulnerability required local access to exploit, meaning it did not enable remote code execution or compromise systems over the network. DIB organizations should care because it highlights the importance of patching known vulnerabilities promptly, as this CVE was listed in CISA's KEV catalog, indicating it was actively exploited in the wild. The failure stems from an unpatched flaw in the XPC implementation in Admin Framework, which could be leveraged by attackers with physical or local access to escalate privileges.
Shame score — The vulnerability was actively exploited in the wild and required patching, but it was not a zero-day or remote exploit, limiting its immediate catastrophic impact while still representing a significant avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.