CVE-2017-13872 is a credential-validation logic error in Directory Utility in macOS High Sierra before Security Update 2017-001. The flaw improperly authenticates disabled accounts during administrative authentication prompts, allowing the root username to be used with an empty password. Repeating the authentication attempt can cause the requested privileged action to be authorized with root administrative privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (modules/exploits/osx/local/root_no_password.rb) that exploits CVE-2017-13872, a critical local privilege escalation vulnerability in Mac OS X 10.13.1 High Sierra. The exploit leverages the fact that the root account can be accessed with an empty password, allowing any local user to gain root privileges. The module writes a payload (default: osx/x64/meterpreter_reverse_tcp) to a temporary file in /tmp, makes it executable, and then executes it as root using AppleScript with the root account and an empty password. The exploit is operational and provides a root shell or Meterpreter session on the target. The code is written in Ruby and is designed to be used within the Metasploit framework. No network endpoints are hardcoded; the only fingerprintable endpoint is the temporary file path used for payload execution.
This repository contains a single Metasploit auxiliary scanner module targeting the Apple Remote Desktop (ARD) root vulnerability (CVE-2017-13872) in unpatched macOS High Sierra systems. The module attempts to enable and set the root account password on the target system via the VNC/ARD protocol (default port 5900). The exploit can set the root password to a user-supplied value or a randomly generated one, and then attempts to authenticate as root. If successful, it logs the credentials for later use. The code is written in Ruby and leverages Metasploit's framework for network scanning and credential management. The exploit is operational and provides a direct method to gain root access on vulnerable systems. No hardcoded IPs or domains are present; the only fingerprintable endpoint is the use of TCP port 5900 (VNC/ARD).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.