CVE-2017-13872
HIGHApple <macOS High Sierra - Privilege Escalation
Title source: llmDescription
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Utility" component. It allows attackers to obtain administrator access without a password via certain interactions involving entry of the root user name.
Exploits (5)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalmacos
https://www.exploit-db.com/exploits/43201
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/vnc/ard_root_pw.rb
metasploit
WORKING POC
EXCELLENT
by chethan177, lemiorhan, timwr · rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/local/root_no_password.rb
Scores
CVSS v3
8.1
EPSS
0.7666
EPSS Percentile
99.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (3)
apple/mac_os_x
10.13.0
apple/mac_os_x
10.13.1
n/a/macOS High Sierra
macOS High Sierra
Published
Nov 29, 2017
Tracked Since
Feb 18, 2026