CVE-2017-2388
MEDIUMmacOS < 10.12.4 - Denial of Service via IOFireWireFamily NULL Pointer Dereference
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-2388. PoCs published by Brandon Azad, bazad.
AI-analyzed exploit summary This exploit triggers a NULL pointer dereference in IOFireWireUserClient::setAsyncRef_IsochChannelForceStop by creating an isochronous channel and then forcing it to stop. The vulnerability leads to a kernel panic, resulting in a denial of service (DoS).
Description
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
Exploits (2)
This exploit triggers a NULL pointer dereference in IOFireWireUserClient::setAsyncRef_IsochChannelForceStop by creating an isochronous channel and then forcing it to stop. The vulnerability leads to a kernel panic, resulting in a denial of service (DoS).
This is a working proof-of-concept exploit for CVE-2017-2388, a NULL pointer dereference in IOFireWireUserClient on macOS. It triggers a denial of service by calling setAsyncRef_IsochChannelForceStop with a NULL handle.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H