New privilege escalation exploit discovered in OS X Yosemite, also affects just-released 10.10.5

Just days after patching the DYLD_PRINT_TO_FILE vulnerability with a new OS X point release, Apple’s desktop operating system has been hit with yet another zero-day exploit that would allow an attacker to gain root access without using a password.

The exploit was discovered by Italian developer Luca Todesco, who relies on a combination of attacks — including a null pointer dereference in OS X’s IOKit — to drop a proof-of-concept payload into a root shell. It affects every version of OS X Yosemite, but seems to have been mitigated in OS X El Capitan, which is nearing release.

Tags: 

Read more: New privilege escalation exploit discovered in OS X Yosemite, also affects just-released 10.10.5

Story added 18. August 2015, content source with full text you can find at link above.