VYPR
Unrated severityNVD Advisory· Published Jan 18, 2007· Updated Jun 16, 2026

CVE-2007-0345

CVE-2007-0345

Description

The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.

Affected products

2
  • cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*
    • (no CPE)range: = 10.4.8

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.