Record summary

CVE-2014-8835 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.

Description

The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type, which allows attackers to execute arbitrary code by providing a crafted dictionary to sysmond, related to an "XPC type confusion" issue.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBApple Mac OSX 10.9.x - sysmond XPC Privilege EscalationExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details

References

9