CVE-2017-7149 is a high-severity vulnerability affecting macOS versions prior to 10.13 Supplemental Update, specifically within the StorageKit component. This flaw allows an authenticated local attacker to discover passwords for APFS encrypted volumes. The vulnerability arises because Disk Utility inadvertently stored the actual password as the hint value. While there is no known active exploitation or publicly available exploit code, the potential impact is significant, as it grants full confidentiality, integrity, and availability compromise of affected volumes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.13CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.