Lucene search

K
hiveproHiveForce LabHIVEPRO:8AF6D26DCA74110BAC16966E03E4BF07
HistoryNov 11, 2022 - 1:49 p.m.

Apple addresses the macOS code execution flaws

2022-11-1113:49:02
HiveForce Lab
www.hivepro.com
86
apple
macos
code execution
flaws
patched
vulnerability
integer overflow
arbitrary code
cve-2022-40303
cve-2022-40304
denial of service
libxml2
reference cycles

0.005 Low

EPSS

Percentile

75.8%

Threat Level Vulnerability Report For a detailed threat advisory, download the pdf file here Summary MacOS Ventura contains two security flaws that can be exploited to cause an integer overflow and execute arbitrary code. The CVE-2022-40303 vulnerability exists as a result of an integer overflow in parse.c while processing exploitation trigger material and executing arbitrary code on the susceptible system. A denial of service (DoS) attack will follow the exploit of CVE-2022-40304, a vulnerability in entities.c mirrored in the way libxml2 controls reference cycles.