ID

VAR-201702-0353


CVE

CVE-2016-4780


TITLE

Apple OS X of Thunderbolt Component vulnerable to arbitrary code execution in privileged context

Trust: 0.8

sources: JVNDB: JVNDB-2016-007371

DESCRIPTION

An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Thunderbolt" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app. Apple macOS is prone to an arbitrary code-execution vulnerability. An attacker can leverage this issue to execute arbitrary code with kernel privileges. Failed exploit attempts will likely result in denial-of-service conditions. Versions prior to macOS 10.12.1 are vulnerable. Apple macOS Sierra is a dedicated operating system developed by Apple for Mac computers. Thunderbolt is one of the general-purpose IO interfaces

Trust: 1.98

sources: NVD: CVE-2016-4780 // JVNDB: JVNDB-2016-007371 // BID: 96332 // VULHUB: VHN-93599

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:lteversion:10.12.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.12

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.12.0

Trust: 0.6

vendor:applemodel:macosscope:eqversion:10.12

Trust: 0.3

vendor:applemodel:macosscope:neversion:10.12.1

Trust: 0.3

sources: BID: 96332 // JVNDB: JVNDB-2016-007371 // CNNVD: CNNVD-201702-717 // NVD: CVE-2016-4780

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-4780
value: HIGH

Trust: 1.0

NVD: CVE-2016-4780
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201702-717
value: CRITICAL

Trust: 0.6

VULHUB: VHN-93599
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2016-4780
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-93599
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-4780
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-93599 // JVNDB: JVNDB-2016-007371 // CNNVD: CNNVD-201702-717 // NVD: CVE-2016-4780

PROBLEMTYPE DATA

problemtype:CWE-476

Trust: 1.9

sources: VULHUB: VHN-93599 // JVNDB: JVNDB-2016-007371 // NVD: CVE-2016-4780

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201702-717

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201702-717

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-007371

PATCH

title:Apple security updatesurl:https://support.apple.com/en-us/HT201222

Trust: 0.8

title:APPLE-SA-2016-10-24-2 macOS Sierra 10.12.1url:https://lists.apple.com/archives/security-announce/2016/Oct/msg00001.html

Trust: 0.8

title:HT207275url:https://support.apple.com/en-us/HT207275

Trust: 0.8

title:HT207275url:https://support.apple.com/ja-jp/HT207275

Trust: 0.8

title:Apple macOS Sierra Thunderbolt Fixes for component security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=68136

Trust: 0.6

sources: JVNDB: JVNDB-2016-007371 // CNNVD: CNNVD-201702-717

EXTERNAL IDS

db:NVDid:CVE-2016-4780

Trust: 2.8

db:JVNid:JVNVU90743185

Trust: 0.8

db:JVNDBid:JVNDB-2016-007371

Trust: 0.8

db:CNNVDid:CNNVD-201702-717

Trust: 0.7

db:BIDid:96332

Trust: 0.4

db:VULHUBid:VHN-93599

Trust: 0.1

sources: VULHUB: VHN-93599 // BID: 96332 // JVNDB: JVNDB-2016-007371 // CNNVD: CNNVD-201702-717 // NVD: CVE-2016-4780

REFERENCES

url:https://support.apple.com/ht207275

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-4780

Trust: 0.8

url:http://jvn.jp/vu/jvnvu90743185/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-4780

Trust: 0.8

url:https://www.apple.com/

Trust: 0.3

url:http://www.apple.com/macosx/

Trust: 0.3

url:https://support.apple.com/en-us/ht207275

Trust: 0.3

sources: VULHUB: VHN-93599 // BID: 96332 // JVNDB: JVNDB-2016-007371 // CNNVD: CNNVD-201702-717 // NVD: CVE-2016-4780

CREDITS

sweetchip of Grayhash

Trust: 0.3

sources: BID: 96332

SOURCES

db:VULHUBid:VHN-93599
db:BIDid:96332
db:JVNDBid:JVNDB-2016-007371
db:CNNVDid:CNNVD-201702-717
db:NVDid:CVE-2016-4780

LAST UPDATE DATE

2025-04-20T22:03:01.219000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-93599date:2017-02-21T00:00:00
db:BIDid:96332date:2017-03-07T01:05:00
db:JVNDBid:JVNDB-2016-007371date:2017-02-28T00:00:00
db:CNNVDid:CNNVD-201702-717date:2017-02-22T00:00:00
db:NVDid:CVE-2016-4780date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-93599date:2017-02-20T00:00:00
db:BIDid:96332date:2016-11-29T00:00:00
db:JVNDBid:JVNDB-2016-007371date:2017-02-28T00:00:00
db:CNNVDid:CNNVD-201702-717date:2017-02-22T00:00:00
db:NVDid:CVE-2016-4780date:2017-02-20T08:59:01.353