Executive brief
A vulnerability in the NeXT NetInfo system, which manages administrative and configuration data, allows a local user to gain full administrative control over the computer. By manipulating specific system properties, an unauthorized user can escalate their privileges to the root level or crash the system entirely. This could lead to a complete compromise of the machine's data and availability.
Technical details
A privilege escalation vulnerability exists in the NeXT NetInfo administrative database system due to improper handling of the '_writers' property. A local attacker with standard user access can modify this property to gain unauthorized write access to sensitive system configurations. By exploiting this flaw, the attacker can escalate their privileges to root or cause a system-wide denial of service. The vulnerability is triggered locally and does not require prior administrative authentication.
Affected products
- NeXT NetInfo
Timeline
- 1997-09-19: disclosed