Mac OS X NFS Mount Privilege Escalation
Posted by deepcore on April 26, 2014 – 2:27 am
This exploit leverage a stack overflow vulnerability to escalate privileges. The vulnerable function nfs_convert_old_nfs_args does not verify the size of a user-provided argument before copying it to the stack. As a result by passing a large size, a local user can overwrite the stack with arbitrary content. Mac OS X Lion Kernel versions equal to and below xnu-1699.32.7 except xnu-1699.24.8 are affected.
Post a reply
You must be logged in to post a comment.