Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-4331. PoCs published by bazad.
AI-analyzed exploit summary This is a working proof-of-concept exploit for CVE-2018-4331, targeting a race condition in GSSCred on macOS. The exploit uses JOP (Jump-Oriented Programming) techniques to achieve arbitrary code execution by reusing existing code fragments in the dyld shared cache.
Description
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
Exploits (1)
This is a working proof-of-concept exploit for CVE-2018-4331, targeting a race condition in GSSCred on macOS. The exploit uses JOP (Jump-Oriented Programming) techniques to achieve arbitrary code execution by reusing existing code fragments in the dyld shared cache.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H