CVE-2007-0023
MEDIUM 6.9EPSS 1.6%
The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.
- CVSS v2.0
- 6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 1.59% chance of exploitation in the next 30 days, 74th percentile
- Published
- 2007-01-24
- Updated
- 2024-08-07