# Apple macOS 10.10 privilege escalation via DYLD_PRINT_TO_FILE

Published: 2015-07-24 · Severity: routine
Canonical: https://vorant.io/reports/80353cc8-4f16-5097-a3c5-655de83c6b0b/apple-macos-10-10-privilege-escalation-via-dyld-print-to-file

> Environment variable overflow in macOS 10.10.0–10.10.4 allows local privilege escalation through arbitrary file write.

A local privilege escalation vulnerability exists in Apple macOS 10.10 (Yosemite) versions 10.10.0 through 10.10.4. The flaw involves improper handling of the DYLD_PRINT_TO_FILE environment variable, which is used to direct system error logging to a specified file. An attacker can exploit this by overflowing or manipulating the variable to achieve arbitrary file write with elevated privileges, leading to privilege escalation. This vulnerability is specific to macOS 10.10 and does not affect earlier versions. The affected environment variable functionality was introduced in version 10.10, making prior releases unaffected. Patches are available from Apple and defenders should apply them immediately to affected systems.

## Mentioned in this report

- Vulnerabilities: CVE-2015-7033

Source reporting: https://www.cert.ssi.gouv.fr/alerte/CERTFR-2015-ALE-009

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/80353cc8-4f16-5097-a3c5-655de83c6b0b/apple-macos-10-10-privilege-escalation-via-dyld-print-to-file.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
