CVE-2005-2742

Apple Mac OS X 10.4.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the desktop and bypass the "Require password to wake this computer from sleep or screen saver" setting.

References (4)

Core 4
Core References
US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/p-312.shtml
Vendor Advisory third-party-advisory x_refsource_auscert
http://www.auscert.org.au/5509
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16920/

Scores

EPSS 0.0036
EPSS Percentile 28.5%

Details

Status published
Products (2)
apple/mac_os_x 10.4.2
apple/mac_os_x_server 10.4.2
Published Oct 26, 2005
Tracked Since Feb 18, 2026