Files
CVEs-PoC/2019/CVE-2019-8656.md
T
2024-05-26 14:27:05 +02:00

23 lines
1.2 KiB
Markdown

### [CVE-2019-8656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8656)
![](https://img.shields.io/static/v1?label=Product&message=macOS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%2010.14%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Extracting%20a%20zip%20file%20containing%20a%20symbolic%20link%20to%20an%20endpoint%20in%20an%20NFS%20mount%20that%20is%20attacker%20controlled%20may%20bypass%20Gatekeeper&color=brighgreen)
### Description
This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. Extracting a zip file containing a symbolic link to an endpoint in an NFS mount that is attacker controlled may bypass Gatekeeper.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/0xT11/CVE-POC
- https://github.com/ARPSyndicate/cvemon
- https://github.com/D00MFist/CVE-2019-8656
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/hectorgie/PoC-in-GitHub
- https://github.com/houjingyi233/macOS-iOS-system-security