The Mac Observer

Apple Releases Security Update Affecting Apple Remote Desktop

TMO Talk (0)

Apple has released Security Update 2004-10-27 for Mac OS X. The update deals with an issue that makes it possible for applications to be run with root privileges under certain circumstances involving Apple Remote Desktop. Appleis release notes:

Available for: Apple Remote Desktop Client 1.2.4 with Mac OS X 10.3.x

Impact: An application can be started behind the loginwindow and it will run as root.

Description: For a system with these following conditions

  • Apple Remote Desktop client installed
  • A user on the client system has been enabled with the Open and quit applications privilege
  • The username and password of the ARD user is known
  • Fast user switching has been enabled
  • A user is logged in, and loginwindow is active via Fast User Switching

If the Apple Remote Desktop Administrator application on another system is used to start a GUI application on the client, then the GUI application would run as root behind the loginwindow. This update prevents Apple Remote Desktop from launching applications when the loginwindow is active. This security enhancement is also present in Apple Remote Desktop v2.1. This issue does not affect systems prior to Mac OS X 10.3. Credit to Andrew Nakhla and Secunia Research for reporting this issue.

The update is being recommended for all users, though it only effects Apple Remote Desktop. The update weighs in at 832k, and can be found in Software Update, or on Appleis security update page.

Post A Comment or Log-in. Need an account? Register here.
 

Recent Headlines - Updated February 14th

Mon, 10:30 PM
News - Apple to Live Stream Tim Cook’s Goldman Sachs Speech
8:14 PM
News - Chinese Authorities Seize Apple iPads in Trademark Dispute
6:26 PM
News - Apple Tops Harris Reputation Poll with Record Score
5:33 PM
Mac Geek Gab Podcast - MGG 381: Mac Internet Recovery, HTML on iPad, iDevice Syncing, More!
5:04 PM
Apple Stock Watch - Apple’s Stock Sets New Closing High of $502.60
1:50 PM
News - A Great 3-Minute Video Look at Macworld|iWorld 2012
12:41 PM
Deal Brothers - Mac mini 2.5GHz dual-core Intel Core i5:  $699
11:51 AM
Rumor - Pegatron Forced to Drop Zenbook Due to MacBook Air Similarities
11:00 AM
Apple Stock Watch - Apple’s Stock Breaks $500 Mark For First Time
10:20 AM
News - Apple Announces Foxconn Inspections
9:34 AM
iObserver - AT&T Begins Process Toward Offering Shared Data
9:15 AM
News - Apple Files Motion to Stop Galaxy Nexus Sales in U.S.
 

The Mac Observer Reader Specials

  • TypeStyler 11 is now in the Mac App Store!! -- Special Introductory Price of $59.95!! -- To Buy From The Mac App Store Click Here Now!! Or buy direct from Strider Software.
  • Mac RAM Upgrades: MacBook Pro 16GB kits $475, 8GB Kits for $119.99! iMac 16GB RAM Kits (4x 4GB) for $229.99! Mac Pro Memory 32GB Kit for $399.99, 64GB Kit for $889.99! Mac Hard Drives 2TB Seagate SATA II for $249.99! Click Here!
  • Poker Mac If you're using a Mac, then you've gotta check out Online Poker Mac. This mac poker and online casino mac site actually does the unthinkable, it actually rewards!

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal