CVE-2017-13908

An issue in handling file permissions was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, macOS High Sierra 10.13. A local attacker may be able to execute non-executable text files via an SMB share.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
appleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
applemac_os_x
10.11 ≤
𝑥
< 10.11.6
applemac_os_x
10.12 ≤
𝑥
≤ 10.12.5
applemac_os_x
10.11.6
applemac_os_x
10.11.6:security_update_2016-001
applemac_os_x
10.11.6:security_update_2016-002
applemac_os_x
10.11.6:security_update_2016-003
applemac_os_x
10.11.6:security_update_2017-001
applemac_os_x
10.11.6:security_update_2017-002
applemac_os_x
10.11.6:security_update_2017-003
𝑥
= Vulnerable software versions