By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation
Tech News

Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation

By Viral Trending Content 4 Min Read
Share
SHARE

Jan 14, 2025Ravie LakshmananEndpoint Security / Vulnerability

macOS SIP Vulnerability

Microsoft has shed light on a now-patched security flaw impacting Apple macOS that, if successfully exploited, could have allowed an attacker running as “root” to bypass the operating system’s System Integrity Protection (SIP) and install malicious kernel drivers by loading third-party kernel extensions.

The vulnerability in question is CVE-2024-44243 (CVSS score: 5.5), a medium-severity bug that was addressed by Apple as part of macOS Sequoia 15.2 released last month. The iPhone maker described it as a “configuration issue” that could permit a malicious app to modify protected parts of the file system.

“Bypassing SIP could lead to serious consequences, such as increasing the potential for attackers and malware authors to successfully install rootkits, create persistent malware, bypass Transparency, Consent and Control (TCC), and expand the attack surface for additional techniques and exploits,” Jonathan Bar Or of the Microsoft Threat Intelligence team said.

Cybersecurity

SIP, also called rootless, is a security framework that aims to prevent malicious software installed on a Mac from tampering with the protected parts of the operating system, including /System, /usr, /bin, /sbin, /var, and the apps that come pre-installed on the device.

It works by enforcing various protections against the root user account, allowing modification of these protected parts only by processes that are signed by Apple and have special entitlements to write to system files, such as Apple software updates and Apple installers.

The two entitlements specific to SIP are below –

  • com.apple.rootless.install, which lifts SIP’s file system restrictions for a process with this entitlement
  • com.apple.rootless.install.heritable, which lifts SIP’s file system restrictions for a process and all its child processes by inheriting the com.apple.rootless.install entitlement

CVE-2024-44243, the latest SIP bypass discovered by Microsoft in macOS after CVE-2021-30892 (Shrootless) and CVE-2023-32369 (Migraine), exploits the Storage Kit daemon’s (storagekitd) “com.apple.rootless.install.heritable” entitlement to get around SIP protections.

Specifically, this is achieved by taking advantage of “storagekitd’s ability to invoke arbitrary processes without proper validation or dropping privileges” to deliver a new file system bundle to /Library/Filesystems – a child process of storagekitd – and override the binaries associated with the Disk Utility, which could then be triggered during certain operations such as disk repair.

Cybersecurity

“Since an attacker that can run as root can drop a new file system bundle to /Library/Filesystems, they can later trigger storagekitd to spawn custom binaries, hence bypassing SIP,” Bar Or said. “Triggering the erase operation on the newly created file system can bypass SIP protections as well.”

The disclosure comes nearly three months after Microsoft also detailed another security flaw in Apple’s Transparency, Consent, and Control (TCC) framework in macOS (CVE-2024-44133, CVSS score: 5.5) – aka HM Surf – that could be exploited to access sensitive data.

“Prohibiting third-party code to run in the kernel can increase macOS reliability, the tradeoff being that it reduces monitoring capabilities for security solutions,” Bar Or said.

“If SIP is bypassed, the entire operating system can no longer be considered reliable, and with reduced monitoring visibility, threat actors can tamper with any security solutions on the device to evade detection.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Our Favorite Amazon Streaming Stick Is Almost Half Off

How is Australia working to make data centres more sustainable?

Google Pixel 11 Design Leaked: Two key Changes

Are Biofuels Worse Than Fossil Fuels?

Critical Citrix NetScaler memory flaw actively exploited in attacks

TAGGED: Apple, Cyber Security, Cybersecurity, Internet, Kernel, MacOS, Malware, Microsoft, Security, Technology, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Hottest Celebrity Pics This Week From January 5 — January 13
Next Article Wednesday Briefing: A Major U.S. Senate Hearing
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Our Favorite Amazon Streaming Stick Is Almost Half Off
Tech News
Leafs Score Today: Latest Toronto Maple Leafs Game Result and Key Stats
Sports
US Stocks: S&P, Nasdaq end lower as investors weigh Middle East conflict outlook
Business
Sky price outlook as project diversifies revenue streams and yield strategies
Crypto
How much do you need in a Stocks and Shares ISA for a £10,000 second income?
Business
DNC Playbook Offers Self-Critique of Party’s Organizing Failures Ahead of 2026 Midterms
Politics
Midnight brings a new level of faction cooperation to WoW
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?