Unpatched Kernel-Level Vuln in IBM Security Tool for Apple MacOS Revealed

  /     /     /  
Publicated : 23/11/2024   Category : security


Unpatched Kernel-Level Vuln in IBM Security Tool for Apple MacOS Revealed


Researchers disclose signedness bug in driver used by IBM Trusteer Rapport endpoint security tool after IBM fails to deliver timely patch.



A kernel-level bug in an endpoint security tool for MacOS remains unpatched after IBM was unable to deliver a patch within the vulnerability researchers 120-day disclosure deadline.
IBM Trusteer Rapport is endpoint security software that protects confidential data like access credentials. Researchers from Trustwave SpiderLabs discovered a signedness bug in the handling of user-supplied buffers on a driver used by Trusteer Rapport on MacOS. The bug can lead to a memory corruption vulnerability in the Apple MacOS kernel and, subsequently, arbitrary code execution in the kernel. 
Trustwave SpiderLabs researchers first reported the bug to IBM Aug. 15 and have been working with the IBM Security Vulnerability Management Team since then, researchers wrote Thursday. When IBM was unable to provide a patch within Trustwaves normal 90-day disclosure policy, the researchers granted IBM an additional 30 days. (IBM representatives could not be reached to verify this timeline as of this posting.) When that deadline again passed without a fix, Trustwave opted to publicly disclose the bug.
The good news is that the vulnerability can only be exploited locally. However, there are several exploits in which attackers could obtain arbitrary code executations within the context of the kernel, researchers said. Security teams should take measures to ensure only authorized users can obtain local access to affected machines.
Read more details 
here

 

Last News

▸ Sony, XBox Targeted by DDoS Attacks, Hacktivist Threats ◂
Discovered: 23/12/2024
Category: security

▸ There are plenty of online tools for reporting bugs. ◂
Discovered: 23/12/2024
Category: security

▸ 27 Million South Koreans Hit by Online Gaming Theft. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Unpatched Kernel-Level Vuln in IBM Security Tool for Apple MacOS Revealed