CVE ID | CVE-2014-4391 |
CVSS SCORE | 5.6, AV:L/AC:L/Au:N/C:P/I:C/A:N |
AFFECTED VENDORS |
Apple |
AFFECTED PRODUCTS |
OS X |
VULNERABILITY DETAILS |
The specific flaw exists within Gatekeeper. The issue lies in the usage of signed applications that do not sign the frameworks they depend on. An attacker can leverage this vulnerability to execute code under the context of the user. |
ADDITIONAL DETAILS |
Apple has issued an update to correct this vulnerability. More details can be found at:
http://support.apple.com/kb/HT6535 |
DISCLOSURE TIMELINE |
|
CREDIT | Christopher Hickstein |