Immunity, Inc.
Name rootpipe
CVE CVE-2015-1130
Exploit Pack CANVAS
DescriptionOS X XPC Admin Framework (rootpipe) local privilege escalation
NotesCVE Name: CVE-2015-1130
VENDOR: Apple
Notes:

This is a local privilege escalation affecting all Mac OS X versions from 10.7
up to 10.10.2. We provide both a 32bit and 64bit version of the exploit.

Tested on:
- 10.10.1
- 10.9.5
- 10.9.4
- 10.9.3
- 10.9.2
- 10.9.1
- 10.9
- 10.7.2

Repeatability: Multiple Times
References: https://truesecdev.wordpress.com/2015/04/09/hidden-backdoor-api-to-root-privileges-in-apple-os-x/
CVE Url: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1130

Learn more about the CANVAS Exploit Pack here: CANVAS