1038484vdb entry
http://www.securitytracker.com/id/1038484 CVE-2017-2533
HIGH
Apple macOS - Disk Arbitration Daemon Race Condition
Record summary
CVE-2017-2533 has a selected CVSS score of 7.0 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitration" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApple macOS - Disk Arbitration Daemon Race ConditionExploitDB exploitby phoenhexNot analyzed1 file
References
6zerodayinitiative.com
http://www.zerodayinitiative.com/advisories/ZDI-17-357 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-2533 phoenhex.re
https://phoenhex.re/2017-06-09/pwn2own-diskarbitrationd-privesc support.apple.comConfirmation
https://support.apple.com/HT207797 42146exploit
https://www.exploit-db.com/exploits/42146