JAMF software local permission promotion vulnerability

software:Self Service(JAMF)


Exploit Author:


Vul detail:

1. Set the HTTP and HTTPS proxy to on the MAC
2. Using burpsuite to intercept communication packets between JAMF and the server
3. Administrators can publish bash shell scripts using JAMF by default
4. when user click run, we insert “/Applications/Utilities/Terminal app/Contents/MacOS/Terminal” into the server return packets using burpsuite
5. Obtaining the root command terminal

