CVE-2016-7585

MEDIUM

Apple Mac OS X < 10.12.3 - Cryptographic Issue

Title source: rule

Description

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.

Scores

CVSS v3 6.8
EPSS 0.0008
EPSS Percentile 23.6%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-310
Status published

Affected Products (2)

apple/mac_os_x < 10.12.3
n/a/n/a

Timeline

Published Apr 02, 2017
Tracked Since Feb 18, 2026