CVE-2015-1130
apple mac os x
Published 10 Apr 2015 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Feb 2022, with a remediation deadline of 10 Aug 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
References
- lists.apple.com/archives/security-announce/2015/Apr/msg00001.html · Broken Link, Mailing List, Vendor Advisory
- www.osvdb.org/120418 · Broken Link
- www.securityfocus.com/bid/73982 · Broken Link, Exploit, Third Party Advisory
- www.securitytracker.com/id/1032048 · Broken Link, Third Party Advisory, VDB Entry
- support.apple.com/HT204659 · Vendor Advisory
- www.exploit-db.com/exploits/36692/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1130 · US Government Resource