Impact
The vulnerability arises from an insecure PIN derivation mechanism in Admin By Request (ABR). A low-privileged user can construct a PIN that matches the expected value, enabling the application to authenticate the attacker as if it were a legitimate Apple-signed process. This authentication bypass leads to privilege escalation, allowing the attacker to gain full administrator rights. The weakness is a classic authorization flaw, cited by CWEs 284, 285, 287, and 327.
Affected Systems
This flaw affects the Admin By Request (ABR) suite. While the precise affected releases are not enumerated in the advisory, all versions lacking the vendor’s latest patch are potentially vulnerable. Users should check the revision history on the vendor’s site and update immediately if an unpatched release is in use.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered high severity, yet the EPSS score of less than 1% indicates that exploitation is currently unlikely. It is not listed in the CISA KEV catalog. The attack requires local access to send crafted Cross-Process Communication messages that impersonate an Apple‑signed process; thus an attacker must be able to execute code on the target machine to leverage the flaw.
OpenCVE Enrichment