Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions
ID: 1ac90cd8-d49c-530b-8d4b-5e6cbb2bbfc2
STIX ID: report--1ac90cd8-d49c-530b-8d4b-5e6cbb2bbfc2
Feed Name: Microsoft Security
Threat Score
Microsoft Threat Intelligence discloses CVE-2024-44243, a macOS System Integrity Protection (SIP) bypass where the storagekitd daemon can be induced to spawn third-party user-filesystem binaries (from /Library/Filesystems bundles), allowing an attacker with local root to load third-party kernel extensions and potentially install rootkits or evade security; Apple released a fix on 2024-12-11 and users are advised to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
