[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-50337-5

Platform: cpe:/o:apple:mac_os_14Date: (C)2024-01-24   (M)2024-01-24



Safari will automatically run or execute what it considers safe files. This can include installers and other files that execute on the operating system. Safari evaluates file safety by using a list of filetypes maintained by Apple.The list of files include text, image, video and archive formats that would be run in the context of the OS rather than the browser. Rationale:Hackers have taken advantage of this setting via drive-by attacks. These attacks occur when a user visits a legitimate website that has been corrupted. The user unknowingly downloads a malicious file either by closing an infected pop-up or hovering over a malicious banner.An attacker can create a malicious file that will fall within Safari's safe file list that will download and execute without user input. Impact:Apple considers many files that the operating system itself auto-executes as "safe files." Many of these files could be malicious and could execute locally without the user even knowing that a file of a specific type had been downloaded. Remediation: Profile Method: Create or edit a configuration profile with the following information: 1. The PayloadType string is com.apple.Safari 2. The key to include is AutoOpenSafeDownloads 3. The key must be set to: <false/>


Parameter:

[Yes/No]


Technical Mechanism:

Remediation: Profile Method: Create or edit a configuration profile with the following information: 1. The PayloadType string is com.apple.Safari 2. The key to include is AutoOpenSafeDownloads 3. The key must be set to: false/

CCSS Severity:CCSS Metrics:
CCSS Score : 9.6Attack Vector: NETWORK
Exploit Score: 2.8Attack Complexity: LOW
Impact Score: 6.0Privileges Required: NONE
Severity: CRITICALUser Interaction: REQUIRED
Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HScope: CHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:97012


OVAL    1
oval:org.secpod.oval:def:97012

© SecPod Technologies