CVE-2017-13872
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Utility" component. It allows attackers to obtain administrator access without a password via certain interactions involving entry of the root user name.
- Affected products
- Macos High Sierra
- Apple Mac Os X
- = 10.13.0, 10.13.1
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 36.8% (98th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2017-11-29
CVE-2017-13872 at NVD
8 known exploits for CVE-2017-13872
Proof-of-concept code and exploit modules indexed by Sploitus
Apple Remote Desktop Root
rootOS - macOS Root Helper
Apple Remote Desktop Root Vulnerability
Apple macOS 10.13.1 High Sierra - Blank Root Local Privilege Escalation Vulnerability
macOS High Sierra - Root Privilege Escalation (CVE-2017-13872)
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation (Metasploit)
Mac OS X Root Privilege Escalation
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation