CVE-2014-1264

macOS < 10.9.2 - Unintended Access Restriction Bypass via Damaged ACL

Title source: llm
STIX 2.1

Description

Finder in Apple OS X before 10.9.2 does not ensure ACL integrity after the viewing of file ACL information, which allows local users to bypass intended access restrictions in opportunistic circumstances via standard filesystem operations on a file with a damaged ACL.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6150

Scores

EPSS 0.0033
EPSS Percentile 25.8%

Details

CWE
CWE-264
Status published
Products (2)
apple/mac_os_x 10.9
apple/mac_os_x < 10.9.1
Published Feb 27, 2014
Tracked Since Feb 18, 2026