An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.
oryginał ENCVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NCarbonblack Carbon Black Cb
APPCarbonblackwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2016-9568CRITICAL9.8PL ✓ten sam vendor
Carbon Black Sensor — nieautoryzowany dostęp przez nieuprzywilejowanego użytkownika
CVE-2016-9570HIGH7.5ten sam vendor
cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid ...
CVE-2016-9569MEDIUM4.4ten sam vendor
The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial...
CVE-2014-1615MEDIUM6.8ten sam vendor
Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers...