CVE-2018-4170 is a local privilege escalation vulnerability affecting macOS versions prior to 10.13.4. It allows a local user to discover a password by observing process arguments during sysadminctl execution, impacting the Admin Framework component. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires local user access, but can lead to high confidentiality, integrity, and availability impacts. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.13.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.