Skip to main content

DEPRECATED: Code

CVE-2014-4498

Severity Medium
Score 4.7/10

Summary

The CPU Software in Apple OS X before 10.10.2 allows physically proximate attackers to modify firmware during the EFI update process by inserting a Thunderbolt device with crafted code in an Option ROM, aka the "Thunderstrike" issue.

  • MEDIUM
  • LOCAL
  • NONE
  • COMPLETE
  • NONE
  • NONE

CWE-17 - DEPRECATED: Code

This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.

References

Advisory Timeline

  • Published