CVE-2017-13872 is a critical privilege escalation vulnerability affecting macOS High Sierra before Security Update 2017-001, specifically within the "Directory Utility" component. This flaw allows an attacker to gain administrator (root) access without a password through specific interactions involving the root username. With a CVSS score of 8.1 (HIGH) and an EPSS score indicating high exploitability, the impact is severe, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV, public exploit code is readily available via Metasploit and ExploitDB, and it garnered significant community discussion and media coverage at the time of its discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.13.0CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.13.0:*:*:*:*:*:*:* | ||
10.13.1CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.13.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.