Lucene search

K
kasperskyKaspersky LabKLA11592
HistoryOct 07, 2019 - 12:00 a.m.

KLA11592 Multiple vulnerabilities in Apple iTunes

2019-10-0700:00:00
Kaspersky Lab
threats.kaspersky.com
41

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.452

Percentile

97.5%

Multiple vulnerabilities were found in Apple iTunes. Malicious users can exploit these vulnerabilities to execute arbitrary code, perform cross-site scripting attack, cause denial of service.

Below is a complete list of vulnerabilities:

  1. Vulnerabilitiy in WebKit can be exploited remotely via specially crafted text file to execute arbitrary code;
  2. Vulnerabilitiy in WebKit can be exploited remotely via specially crafted web content to perform cross-site scripting attacks;
  3. Vulnerabilitiy in UIFoundation can be exploited remotely via specially crafted text file to execute arbitrary code;
  4. Vulnerabilitiy in CoreCrypto can be exploited remotely to cause denial of service;
  5. Vulnerabilitiy in CoreMedia can be exploited remotely via specially crafted web content to execute arbitrary code;
  6. Vulnerabilitiy in Foundation can be exploited remotely to execute arbitrary code;
  7. A memory corruption vulnerability in libxml2 can be exploited remotely to execute arbitrary code;
  8. A memory corruption vulnerability in libxslt can be exploited remotely to execute arbitrary code;

Original advisories

HT210635

Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

Apple-iTunes

CVE list

CVE-2019-8726 high

CVE-2019-8733 high

CVE-2019-8707 high

CVE-2019-8719 warning

CVE-2019-8745 high

CVE-2019-8625 warning

CVE-2019-8735 high

CVE-2019-8763 high

CVE-2019-8741 critical

CVE-2019-8825 high

CVE-2019-8746 critical

CVE-2019-8749 critical

CVE-2019-8756 critical

CVE-2019-8750 critical

CVE-2019-8764 warning

CVE-2019-8710 high

CVE-2019-8728 high

CVE-2019-8734 high

CVE-2019-8743 high

CVE-2019-8751 high

CVE-2019-8752 high

CVE-2019-8765 high

CVE-2019-8766 high

CVE-2019-8773 high

CVE-2019-8762 warning

Solution

Update to latest version

Download iTunes

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • XSS/CSS

Cross site scripting. Exploitation of vulnerabilities with this impact can lead to partial interception of information transmitted between user and site.

Affected Products

  • Apple iTunes earlier thanΒ 12.10.1

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.452

Percentile

97.5%