CVE-2017-2489
MEDIUMmacOS < 10.12.4 - Unauthorized Kernel Memory Exposure via Intel Graphics Driver
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-2489. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a lack of bounds checking in AppleIntelCapriController::getDisplayPipeCapability to disclose kernel memory, potentially defeating kASLR by reading vtable pointers. It uses IOConnectCallMethod to trigger the vulnerability and dump memory contents.
Description
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
Exploits (1)
This exploit leverages a lack of bounds checking in AppleIntelCapriController::getDisplayPipeCapability to disclose kernel memory, potentially defeating kASLR by reading vtable pointers. It uses IOConnectCallMethod to trigger the vulnerability and dump memory contents.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N