VYPR
High severity7.8NVD Advisory· Published Jan 11, 2016· Updated May 6, 2026

CVE-2015-6980

CVE-2015-6980

Description

Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to gain privileges via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Directory Utility in macOS before 10.11.1 mishandles new session authentication, allowing local privilege escalation.

Vulnerability

Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which can allow a local user to gain elevated privileges. The vulnerability exists in the Directory Utility component and affects OS X El Capitan 10.11, OS X Yosemite 10.10.5, and OS X Mavericks 10.9.5 [1]. The specific code path requires that the attacker has local access to the system.

Exploitation

An attacker must have local access to the affected system. The exploitation vector is unspecified in available references, but it is described as local privilege escalation. The attacker would need to trigger the mishandling of authentication for new sessions, possibly through the Directory Utility interface or its associated processes [1].

Impact

Successful exploitation allows a local user to gain elevated privileges beyond their normal access level. The impact is privilege escalation, potentially leading to full control over the affected system. The precise privilege level gained is not disclosed in the available references [1].

Mitigation

The issue is fixed in OS X El Capitan 10.11.1, released on October 21, 2015. Apple has not disclosed a workaround. Users should update to the latest version of OS X El Capitan (10.11.1 or later) [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.