Lucene search

K
kasperskyKaspersky LabKLA12155
HistoryApr 26, 2021 - 12:00 a.m.

KLA12155 Multiple vulnerabilities in Apple iCloud

2021-04-2600:00:00
Kaspersky Lab
threats.kaspersky.com
21
apple icloud
malicious users
coretext
cfnetwork
webkit
information disclosure
memory initialization
cross-site scripting
webrtc
use after free
cve-2021-1811
cve-2021-1857
cve-2021-1825
cve-2020-7463
update
security bypass
cross site scripting

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.003

Percentile

71.5%

Multiple vulnerabilities were found in Apple iCloud. Malicious users can exploit these vulnerabilities to obtain sensitive information, perform cross-site scripting attack.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in CoreText can be exploited to obtain sensitive information.
  2. A memory initialization vulnerability in CFNetwork can be exploited to obtain sensitive information.
  3. A cross-site-scripting (XSS) vulnerability in WebKit can be exploited to perform cross-site scripting attack.
  4. A use after free vulnerability in WebRTC can be exploited to cause denial of service or execute arbitrary code.

Original advisories

About the security content of iCloud for Windows 12.3

Related products

Apple-iCloud

CVE list

CVE-2021-1811 high

CVE-2021-1857 high

CVE-2021-1825 high

CVE-2020-7463 high

Solution

Update to the latest version

Download iCloud

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • XSS/CSS

Cross site scripting. Exploitation of vulnerabilities with this impact can lead to partial interception of information transmitted between user and site.

Affected Products

  • Apple iCloud for Windows earlier than 12.3

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.003

Percentile

71.5%