Lucene search

K
kasperskyKaspersky LabKLA12156
HistoryApr 22, 2021 - 12:00 a.m.

KLA12156 Multiple vulnerabilities in Apple iTunes

2021-04-2200:00:00
Kaspersky Lab
threats.kaspersky.com
44
apple itunes
vulnerabilities
cross-site scripting
memory initialization
use after free
information disclosure
update
sensitive information
denial of service
osi
sb
xss/css
webkit
cfnetwork
webrtc
coretext

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.003

Percentile

71.5%

Multiple vulnerabilities were found in Apple iTunes. Malicious users can exploit these vulnerabilities to perform cross-site scripting attack, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A cross-site-scripting (XSS) vulnerability in WebKit can be exploited to perform cross-site scripting attack.
  2. A memory initialization vulnerability in CFNetwork can be exploited to obtain sensitive information.
  3. A use after free vulnerability in WebRTC can be exploited to cause denial of service or execute arbitrary code.
  4. An information disclosure vulnerability in CoreText can be exploited to obtain sensitive information.

Original advisories

About the security content of iTunes 12.11.3 for Windows

Related products

Apple-iTunes

CVE list

CVE-2021-1811 high

CVE-2021-1857 high

CVE-2021-1825 high

CVE-2020-7463 high

Solution

Update to the latest version

Download iTunes

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • XSS/CSS

Cross site scripting. Exploitation of vulnerabilities with this impact can lead to partial interception of information transmitted between user and site.

Affected Products

  • Apple iTunes earlier than 12.11.3

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.003

Percentile

71.5%