CVE-2010-0512

Mac OS X 10.6 - Unauthenticated Login Window Access Control Bypass via Group Membership

Title source: llm
STIX 2.1

Description

The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39153
Patch, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
Patch, Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4077

Scores

EPSS 0.0166
EPSS Percentile 74.3%

Details

CWE
CWE-264
Status published
Products (6)
apple/mac_os_x 10.6.0
apple/mac_os_x 10.6.1
apple/mac_os_x 10.6.2
apple/mac_os_x_server 10.6.0
apple/mac_os_x_server 10.6.1
apple/mac_os_x_server 10.6.2
Published Mar 30, 2010
Tracked Since Feb 18, 2026