Skip to main content
Question

Vulnerability 10.13 - Root

  • November 28, 2017
  • 82 replies
  • 368 views

Show first post

82 replies

Forum|alt.badge.img+15
  • Valued Contributor
  • November 29, 2017

Read up, matin! ;) . (released at 8:00 this AM)


Forum|alt.badge.img+1
  • New Contributor
  • November 29, 2017

Anybody know a way to create a Smart Group to verify if the patch was installed on systems?


mm2270
Forum|alt.badge.img+24
  • Legendary Contributor
  • November 29, 2017

@scharest Per the Apple support article detailing the patch, the new OS build version will be "17B1002", so you can use the "Operating System Build" criteria to build a Smart Group that has build "17B1002" installed. That should group machines that have the patch applied.
If you want the reverse, i.e, machines running High Sierra but don't have the patch installed, use these:

Operating System Version | greater than or equal | "10.13" and Operating System Build | is not | "17B1002"

Forum|alt.badge.img+2
  • New Contributor
  • November 29, 2017

If anyone is looking for an link from Apple to download the security update.

https://support.apple.com/kb/DL1942?viewlocale=en_US&locale=en_US


ThijsX
Forum|alt.badge.img+20
  • Employee
  • November 29, 2017

NIce,

i used below article to deploy that one specific update.

https://www.jamf.com/jamf-nation/third-party-products/files/937/apple-software-update-script


Forum|alt.badge.img+12
  • Valued Contributor
  • November 30, 2017

I just rebooted my Mac and the BuildVersion is now 17B1003. It looks like they re-released the patch.

Security Update 2017-001

Looks like the original patch broke other things:
https://www.engadget.com/2017/11/30/apples-high-sierra-security-patch-affected-mac-file-sharing/


Forum|alt.badge.img+15
  • Valued Contributor
  • November 30, 2017

The re-release also applies to 10.13 (vs. 10.13.1).