Lucene search

K
zdiNiklas Baumstark and Samuel GroßZDI-17-347
HistoryMay 15, 2017 - 12:00 a.m.

(Pwn2Own) Apple macOS speechsynthesisd Unsigned Dylib Loading Privilege Escalation Vulnerability

2017-05-1500:00:00
Niklas Baumstark and Samuel Groß
www.zerodayinitiative.com
18

EPSS

0.001

Percentile

30.4%

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Apple macOS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the speechsynthesisd service. The issue results from the lack of proper validation of a library prior to loading it. An attacker can leverage this vulnerability to escalate privileges under the context of the current service.

EPSS

0.001

Percentile

30.4%