CVE-2019-8513
HIGHMac OS X TimeMachine (tmdiagnose) Command Injection Privilege Escalation
Title source: metasploitExploitation Summary
EIP tracks 2 public exploits for CVE-2019-8513.
PoCs published by Metasploit, CodeColorist, timwr, including Metasploit module exploits/osx/local/timemachine_cmd_injection.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in the `tmdiagnose` binary on macOS <= 10.14.3, allowing privilege escalation to root by crafting a malicious disk label. The exploit uploads and executes a payload via a specially crafted volume label.
Description
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell commands.
Exploits (2)
This Metasploit module exploits a command injection vulnerability in the `tmdiagnose` binary on macOS <= 10.14.3, allowing privilege escalation to root by crafting a malicious disk label. The exploit uploads and executes a payload via a specially crafted volume label.
This Metasploit module exploits a command injection vulnerability in the `tmdiagnose` binary on macOS <= 10.14.3. It leverages a specially crafted disk label with backtick characters to execute arbitrary commands as root.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H