CVE-2017-2390
MEDIUMApple <10.3 - Local Privilege Escalation
Title source: llmDescription
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves symlink mishandling in the "libarchive" component. It allows local users to change arbitrary directory permissions via unspecified vectors.
References (6)
Scores
CVSS v3
5.5
EPSS
0.0009
EPSS Percentile
24.6%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-59
Status
published
Affected Products (5)
apple/iphone_os
< 10.2.1
apple/mac_os_x
< 10.12.3
apple/tvos
< 10.1.1
apple/watchos
< 3.1.3
n/a/n/a
Timeline
Published
Apr 02, 2017
Tracked Since
Feb 18, 2026