CVE-2009-1235
Apple Mac OS X < 10.5.6 - Access Control
Title source: ruleDescription
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.
Exploits (1)
References (13)
Scores
EPSS
0.0020
EPSS Percentile
42.5%
Details
CWE
CWE-264
Status
published
Products (47)
apple/mac_os_x
10.0
apple/mac_os_x
10.0.0
apple/mac_os_x
10.0.1
apple/mac_os_x
10.0.2
apple/mac_os_x
10.0.3
apple/mac_os_x
10.0.4
apple/mac_os_x
10.1
apple/mac_os_x
10.1.0
apple/mac_os_x
10.1.1
apple/mac_os_x
10.1.2
... and 37 more
Published
Apr 02, 2009
Tracked Since
Feb 18, 2026