{"id":14499,"date":"2021-11-01T14:59:35","date_gmt":"2021-11-01T18:59:35","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=14499"},"modified":"2021-11-26T21:40:57","modified_gmt":"2021-11-27T02:40:57","slug":"microsoft-discovers-macos-bug-that-can-bypass-sip","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/microsoft-discovers-macos-bug-that-can-bypass-sip\/","title":{"rendered":"Microsoft Discovers MacOS Bug That Can bypass SIP"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Microsoft 365 Defender Research Team recently discovered a new macOS vulnerability nicknamed &#8220;Shrootless&#8221; and tracked it as CVE-2021-30892, a vulnerability that can misuse privilege inheritance in macOS &#8216;System Integrity Protection (SIP) thereby giving room for the execution of arbitrary code with root privileges.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reportedly, the vulnerability has already been patched in the three supported versions of macOS (Monterey 12.0.1, Catalina with Security Updates 2021-007, and Big Sur 11.6.1) although there are indications that older versions of OS X running SIP including OS X 10.11 and later may still be vulnerable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When examining how Shrootless works, the first thing to understand is how SIP works. SIP as we have it adds kernel-level that prevent certain files on the disk and certain processes in memory from being changed, even with root privileges.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The bug then takes advantage of the fact that the kernel can modify protected locations as needed, even if root privileges are no longer sufficient to modify important system files.<\/p>\n\n\n<p>For more information, read the <a href=\"https:\/\/arstechnica.com\/gadgets\/2021\/10\/microsoft-reports-sip-bypassing-shrootless-vulnerability-in-macos\/\" target=\"_blank\" rel=\"noopener\">original story<\/a> in Arstechnica.<\/p>","protected":false},"excerpt":{"rendered":"<p>The Microsoft 365 Defender Research Team recently discovered a new macOS vulnerability nicknamed &#8220;Shrootless&#8221;  that can misuse privilege inheritance in macOS &#8216;System Integrity Protection (SIP)<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57],"tags":[62],"class_list":["post-14499","post","type-post","status-publish","format-standard","hentry","category-companies","tag-microsoft"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/14499","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=14499"}],"version-history":[{"count":3,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/14499\/revisions"}],"predecessor-version":[{"id":14518,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/14499\/revisions\/14518"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=14499"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=14499"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=14499"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}