Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-13878. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates an out-of-bounds read vulnerability in AppleIntelCapriController::getDisplayPipeCapability, allowing arbitrary kernel memory disclosure due to lack of bounds checking on attacker-controlled input.
Description
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (out-of-bounds read and system crash).
Exploits (1)
This exploit demonstrates an out-of-bounds read vulnerability in AppleIntelCapriController::getDisplayPipeCapability, allowing arbitrary kernel memory disclosure due to lack of bounds checking on attacker-controlled input.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H