Blog | G5 Cyber Security

Vulnerability Spotlight: A deep dive into macOS SMB server

An adversary could exploit these vulnerabilities to carry out a variety of malicious actions, including revealing sensitive information on the server, bypassing certain cryptographic checks, causing a denial of service or executing remote code on the targeted server. Users are encouraged to update to the latest macOS version as soon as possible to patch these vulnerabilities. The vulnerabilities are all on the post-authentication attack surface, which lowers their severity, but they are readily exploitable in environments with advanced authentication mechanisms. The main server binary lives in `/usr/sbin/smbd` and can be started either through `launchd` or manually.”]

Source: https://blog.talosintelligence.com/2021/06/vuln-spotlight-smb-mac-deep-dive.html

Exit mobile version