CVE-2011-3212

Apple Mac OS X 10.7 - Unprotected User Data Exposure via FileVault Encryption

Title source: llm
STIX 2.1

Description

CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/76362
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5002
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5281
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50085

Scores

EPSS 0.0038
EPSS Percentile 30.8%

Details

CWE
CWE-310
Status published
Products (4)
apple/mac_os_x 10.7.0
apple/mac_os_x 10.7.1
apple/mac_os_x_server 10.7.0
apple/mac_os_x_server 10.7.1
Published Oct 14, 2011
Tracked Since Feb 18, 2026