CVE-2011-0182 describes a privilege escalation vulnerability in Apple Mac OS X before version 10.6.7, affecting both client and server editions. The flaw resides in the i386_set_ldt system call's improper handling of call gates, allowing a local attacker to gain elevated privileges. With a CVSS score of 7.2 (High), this vulnerability is easily exploitable locally with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an exploit for a denial-of-service condition related to this vulnerability exists on ExploitDB, though no Metasploit or Nuclei modules are available. Community discussion and media coverage for this decade-old CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.6.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.6.0CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.6.0:*:*:*:*:*:*:* | ||
10.6.1CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.6.1:*:*:*:*:*:*:* | ||
10.6.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.6.2:*:*:*:*:*:*:* | ||
10.6.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.6.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.