CVE-2017-7149
Apple Security Advisory 2017-10-05-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.
Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de macOS anteriores a la 10.13 Supplemental Update. El problema implica el componente "StorageKit". Permite que atacantes averigüen las contraseñas para volúmenes codificados por APFS leyendo sugerencias de Disk Utility debido a que el valor de sugerencia almacenado se ha establecido accidentalmente como la propia contraseña, no como el valor de sugerencia introducido.
macOS High Sierra 10.13 Supplemental Update is now available and addresses a password hint issue and keychain extraction vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-17 CVE Reserved
- 2017-10-05 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101178 | Third Party Advisory | |
http://www.securitytracker.com/id/1039513 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.apple.com/HT208165 | 2019-10-03 |