Lucene search

K
kasperskyKaspersky LabKLA20116
HistoryDec 13, 2022 - 12:00 a.m.

KLA20116 Multiple vulnerabilities in Apple iCloud

2022-12-1300:00:00
Kaspersky Lab
threats.kaspersky.com
14
apple icloud
webkit
imageio
cve-2022-46692
cve-2022-46693
cve-2022-46698
security bypass
arbitrary code execution
obtain sensitive information
update required

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.8%

Multiple vulnerabilities were found in Apple iCloud. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Security vulnerability in WebKit can be exploited to bypass security restrictions.
  2. Out of bounds write vulnerability in ImageIO can be exploited to execute arbitrary code.
  3. Information disclosure vulnerability in WebKit can be exploited to obtain sensitive information.

Original advisories

About the security content of iCloud for Windows 14.1

Related products

Apple-iCloud

CVE list

CVE-2022-46692 high

CVE-2022-46693 critical

CVE-2022-46698 high

Solution

Update to the latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • Apple iCloud earlier than 14.1

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.8%