Lucene search

K
cveAppleCVE-2024-40811
HistoryJul 29, 2024 - 11:15 p.m.

CVE-2024-40811

2024-07-2923:15:13
CWE-281
apple
web.nvd.nist.gov
30
cve-2024-40811
macos sonoma
file system modification

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

9.4%

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to modify protected parts of the file system.

Affected configurations

Vulners
Vulnrichment
Node
macosRange<14.6
VendorProductVersionCPE
*macos*cpe:2.3:apple:*:macos:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "macOS",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "14.6",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

9.4%