CVE-2015-1130
KEVHIGH 7.8EPSS 9.9%
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 9.89% chance of exploitation in the next 30 days, 95th percentile
- CISA KEV
- added 2022-02-10
- Published
- 2015-04-10
- Updated
- 2025-10-22
Proof-of-concept exploits (3)
- Shmoopi/RootPipe-Demo2★ · 2015-04-10
- davidawad/Python-RootKit-Exploit-OSX22★ · 2015-05-30
- svartkanin/source_code_analyzer0★ · 2019-10-04