Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-4139. PoCs published by Google Security Research.
AI-analyzed exploit summary The code describes a MIG-based vulnerability in macOS's kextd (CVE-2018-4139) where an invalid client port passed by a root user causes a UREF drop, leading to potential privilege escalation. The writeup references a similar exploit (mach_portal) and outlines how this could be exploited to gain kernel code execution.
Description
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Exploits (1)
The code describes a MIG-based vulnerability in macOS's kextd (CVE-2018-4139) where an invalid client port passed by a root user causes a UREF drop, leading to potential privilege escalation. The writeup references a similar exploit (mach_portal) and outlines how this could be exploited to gain kernel code execution.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H