Vulnerability Description
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os X | <= 10.11.0 |
References
- http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.htmlVendor Advisory
- http://packetstormsecurity.com/files/134072/Safari-User-Assisted-Applescript-Exe
- http://www.rapid7.com/db/modules/exploit/osx/browser/safari_user_assisted_apples
- https://support.apple.com/HT205375Vendor Advisory
- https://www.exploit-db.com/exploits/38535/
- http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.htmlVendor Advisory
- http://packetstormsecurity.com/files/134072/Safari-User-Assisted-Applescript-Exe
- http://www.rapid7.com/db/modules/exploit/osx/browser/safari_user_assisted_apples
- https://support.apple.com/HT205375Vendor Advisory
- https://www.exploit-db.com/exploits/38535/
FAQ
What is CVE-2015-7007?
CVE-2015-7007 is a vulnerability with a CVSS score of 7.5 (HIGH). Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via unspecified vectors.
How severe is CVE-2015-7007?
CVE-2015-7007 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7007?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X.