ID

VAR-200609-0377


CVE

CVE-2006-4887


TITLE

Apple Remote Desktop Local Authentication Bypass Vulnerability

Trust: 0.9

sources: BID: 20092 // CNNVD: CNNVD-200609-338

DESCRIPTION

Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote Desktop itself, but in applications that are installed while using it. Apple Remote Desktop is prone to an authentication-bypass vulnerability. A local attacker can exploit this issue to gain superuser privileges to a vulnerable computer. ARD allows UNIX commands to be sent remotely from a management workstation. Since the ARD administrator may have given sudo access, commands sent remotely may run with root privileges. The LoginWindow process belongs to the logged in user. If the system is in the login window, the LoginWindow process will belong to root. If the system is loaded with a disk image that only root can see, the image will try to appear on the desktop, clicking the mouse will force the display of the desktop and menu, and then the user with physical access to the system will be able to see a finder window, and the root user of the home directory. Users can ignore the login window and then gain full root access

Trust: 1.98

sources: NVD: CVE-2006-4887 // JVNDB: JVNDB-2006-001283 // BID: 20092 // VULHUB: VHN-20995

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:lteversion:10.2.8

Trust: 1.8

vendor:applemodel:remote desktopscope:eqversion:2.0.0

Trust: 1.6

vendor:applemodel:remote desktopscope:eqversion:2.1.0

Trust: 1.6

vendor:applemodel:remote desktopscope:eqversion:3.0.0

Trust: 1.6

vendor:applemodel:remote desktopscope:eqversion:2.1

Trust: 0.9

vendor:applemodel:remote desktopscope:eqversion:2.0

Trust: 0.9

vendor:applemodel:remote desktopscope:eqversion:3.0

Trust: 0.9

vendor:applemodel:mac os xscope:eqversion:10.2.8

Trust: 0.6

sources: BID: 20092 // JVNDB: JVNDB-2006-001283 // CNNVD: CNNVD-200609-338 // NVD: CVE-2006-4887

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2006-4887
value: HIGH

Trust: 1.0

NVD: CVE-2006-4887
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200609-338
value: HIGH

Trust: 0.6

VULHUB: VHN-20995
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2006-4887
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-20995
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-20995 // JVNDB: JVNDB-2006-001283 // CNNVD: CNNVD-200609-338 // NVD: CVE-2006-4887

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2006-4887

THREAT TYPE

local

Trust: 0.9

sources: BID: 20092 // CNNVD: CNNVD-200609-338

TYPE

access verification error

Trust: 0.6

sources: CNNVD: CNNVD-200609-338

CONFIGURATIONS

sources: JVNDB: JVNDB-2006-001283

PATCH

title:Top Pageurl:http://www.apple.com/remotedesktop/

Trust: 0.8

sources: JVNDB: JVNDB-2006-001283

EXTERNAL IDS

db:NVDid:CVE-2006-4887

Trust: 2.5

db:BIDid:20092

Trust: 2.0

db:OSVDBid:32260

Trust: 1.7

db:JVNDBid:JVNDB-2006-001283

Trust: 0.8

db:CNNVDid:CNNVD-200609-338

Trust: 0.7

db:BUGTRAQid:20060926 RE: RE: APPLE REMOTE DESKTOP ROOT VULNERAVILITY

Trust: 0.6

db:BUGTRAQid:20060920 RE: APPLE REMOTE DESKTOP ROOT VULNERAVILITY

Trust: 0.6

db:BUGTRAQid:20060918 APPLE REMOTE DESKTOP ROOT VULNERAVILITY

Trust: 0.6

db:XFid:29060

Trust: 0.6

db:VULHUBid:VHN-20995

Trust: 0.1

sources: VULHUB: VHN-20995 // BID: 20092 // JVNDB: JVNDB-2006-001283 // CNNVD: CNNVD-200609-338 // NVD: CVE-2006-4887

REFERENCES

url:http://www.securityfocus.com/bid/20092

Trust: 1.7

url:http://www.osvdb.org/32260

Trust: 1.7

url:http://www.securityfocus.com/archive/1/446371/100/0/threaded

Trust: 1.1

url:http://www.securityfocus.com/archive/1/446751/100/0/threaded

Trust: 1.1

url:http://www.securityfocus.com/archive/1/447043/100/0/threaded

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/29060

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2006-4887

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2006-4887

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/29060

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/446371/100/0/threaded

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/447043/100/0/threaded

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/446751/100/0/threaded

Trust: 0.6

url:http://www.apple.com/remotedesktop/

Trust: 0.3

url:http://www.apple.com/macosx/

Trust: 0.3

url:http://www.apple.com

Trust: 0.3

url:/archive/1/446371

Trust: 0.3

url:/archive/1/447043

Trust: 0.3

sources: VULHUB: VHN-20995 // BID: 20092 // JVNDB: JVNDB-2006-001283 // CNNVD: CNNVD-200609-338 // NVD: CVE-2006-4887

CREDITS

fribitch fribitch@organic.com

Trust: 0.6

sources: CNNVD: CNNVD-200609-338

SOURCES

db:VULHUBid:VHN-20995
db:BIDid:20092
db:JVNDBid:JVNDB-2006-001283
db:CNNVDid:CNNVD-200609-338
db:NVDid:CVE-2006-4887

LAST UPDATE DATE

2025-04-03T22:10:25.233000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-20995date:2018-10-30T00:00:00
db:BIDid:20092date:2006-09-27T22:11:00
db:JVNDBid:JVNDB-2006-001283date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200609-338date:2006-12-06T00:00:00
db:NVDid:CVE-2006-4887date:2025-04-03T01:03:51.193

SOURCES RELEASE DATE

db:VULHUBid:VHN-20995date:2006-09-19T00:00:00
db:BIDid:20092date:2006-09-18T00:00:00
db:JVNDBid:JVNDB-2006-001283date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200609-338date:2006-09-19T00:00:00
db:NVDid:CVE-2006-4887date:2006-09-19T21:07:00