VYPR
Unrated severityNVD Advisory· Published Apr 3, 2019· Updated Aug 5, 2024

CVE-2017-13911

CVE-2017-13911

Description

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capitan 10.11.6 Security Update 2018-002, macOS Sierra 10.12.6 Security Update 2018-002, macOS High Sierra 10.13.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A configuration issue in macOS allowed passwords supplied to sysadminctl to be exposed to other local users, addressed in macOS High Sierra 10.13.4 and security updates.

Vulnerability

A configuration issue in the Admin Framework component of macOS allowed passwords supplied to the sysadminctl command-line tool to be exposed to other local users [1]. The sysadminctl tool required that passwords be passed via command-line arguments, which could be observed by other users on the same system through process listings or other mechanisms. This issue affected versions prior to macOS High Sierra 10.13.4, macOS Sierra 10.13.3 Security Update 2018-002, and macOS X El Capitan 10.11.6 Security Update 2018-002 [1].

Exploitation

To exploit this vulnerability, an attacker would need local user access to the same macOS system and the ability to observe process arguments (e.g., via ps command or /proc). The attacker could then capture the plaintext password passed as an argument to sysadminctl when another local user (including an administrator) invoked that tool [1]. No additional authentication or privileges are required beyond local access.

Impact

Successful exploitation allows an attacker to obtain the plaintext password supplied to sysadminctl, potentially leading to unauthorized access to accounts, privilege escalation, or further compromise of the affected system [1]. The confidentiality of credentials is directly compromised.

Mitigation

Apple addressed the issue by making the password parameter optional in sysadminctl; the tool now prompts for the password interactively instead of accepting it as an argument [1]. The fix is included in macOS High Sierra 10.13.4 (released March 29, 2018), Security Update 2018-002 for macOS Sierra, and Security Update 2018-002 for macOS X El Capitan [1]. Users should update to these versions or later.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.