CVE-2007-0023
The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.
- Affected products
- Cocoa, Macos X, Usernotificationcenter.App, Diskutil
- Apple Mac Os X
- = 10.4.8
- Fix
- Available
- CVSS 2.0
- 6.9 MEDIUM
- EPSS
- 1.5% (72th percentile)
- NVD status
- Modified
- Published
- 2007-01-24
CVE-2007-0023 at NVD
2 known exploits for CVE-2007-0023
Proof-of-concept code and exploit modules indexed by Sploitus