// For flags

CVE-2006-4887

 

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote Desktop itself, but in applications that are installed while using it.

Apple Remote Desktop (ARD) para Mac OS X 10.2.8 y posteriores no quita privilegios en la máquina remota al instalar ciertas aplicaciones, lo cual permite a usuarios locales evitar la autenticación y obtener privilegios seleccionando el icono durante la instalación.
NOTA: Se podría discutir que esta vulnerabilidad no se produce en el mismo Remote Desktop, si no en aplicaciones que son instaladas cuando se está usando.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-09-19 CVE Reserved
  • 2006-09-19 CVE Published
  • 2024-02-12 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apple
Search vendor "Apple"
Apple Remote Desktop
Search vendor "Apple" for product "Apple Remote Desktop"
2.0.0
Search vendor "Apple" for product "Apple Remote Desktop" and version "2.0.0"
-
Affected
Apple
Search vendor "Apple"
Apple Remote Desktop
Search vendor "Apple" for product "Apple Remote Desktop"
2.1.0
Search vendor "Apple" for product "Apple Remote Desktop" and version "2.1.0"
-
Affected
Apple
Search vendor "Apple"
Apple Remote Desktop
Search vendor "Apple" for product "Apple Remote Desktop"
3.0.0
Search vendor "Apple" for product "Apple Remote Desktop" and version "3.0.0"
-
Affected
Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
<= 10.2.8
Search vendor "Apple" for product "Mac Os X" and version " <= 10.2.8"
-
Affected