CVE-2008-2830 describes a privilege escalation vulnerability in Apple Mac OS X 10.4.11, 10.5.4, and other 10.4/10.5 versions. The Open Scripting Architecture improperly loads scripting addition plugins, allowing local users to execute commands with elevated privileges, as demonstrated by targeting the ARDAgent. With a CVSS score of 7.2, this vulnerability is considered highly severe due to its local attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog or showing active exploitation, a public exploit (EDB-31940) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:* | ||
10.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.