Executive brief
A vulnerability in the BuildDisk utility on older NeXT computer systems allows any user with physical or local access to the machine to gain full administrative control. The program fails to verify administrative credentials before performing sensitive operations, which could lead to unauthorized access to all data on the system or a complete system takeover.
Technical details
The BuildDisk utility in NeXTSTEP versions prior to 2.0 contains a privilege escalation vulnerability. The application does not implement an authentication check or password prompt when executed, despite performing actions that require root-level permissions. A local attacker with standard user access can execute the BuildDisk program to gain unauthorized root privileges. This issue was addressed in NeXTSTEP version 2.0.
Affected products
- NeXT NeXTSTEP before 2.0
Timeline
- 1990-10-03: disclosed: Initial publication date
- 1990-10-03: advisory: NVD published date