CVE-2017-13876
HIGH
7,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH
9,3
Source: [email protected]
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete
Description
AI Translation Available
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the 'Kernel' component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0225
Percentile
0,8th
Updated
EPSS Score Trend (Last 90 Days)
119
Improper Restriction of Operations within the Bounds of a Memory Buffer
StableCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Modify Memory
Read Memory
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Applicable Platforms
Languages:
Assembly, C, C++, Memory-Unsafe
Exploit
Apple XNU Kernel - Memory Corruption due to …
VerifiedApple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
View Exploit Code →
Operating System
Watchos by Apple
Version Range Affected
To
4.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Mac Os X by Apple
Version Range Affected
To
10.13.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Iphone Os by Apple
Version Range Affected
To
11.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Tvos by Apple
Version Range Affected
To
11.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://support.apple.com/HT208325
https://support.apple.com/HT208327
https://support.apple.com/HT208331
https://support.apple.com/HT208334
https://www.exploit-db.com/exploits/43325/
http://www.securityfocus.com/bid/102100
http://www.securitytracker.com/id/1039952
http://www.securitytracker.com/id/1039953
http://www.securitytracker.com/id/1039966
https://support.apple.com/HT208325
https://support.apple.com/HT208327
https://support.apple.com/HT208331
https://support.apple.com/HT208334
https://www.exploit-db.com/exploits/43325/
http://www.securityfocus.com/bid/102100
http://www.securitytracker.com/id/1039952
http://www.securitytracker.com/id/1039953
http://www.securitytracker.com/id/1039966