Lucene search

K
kasperskyKaspersky LabKLA49284
HistoryMay 23, 2023 - 12:00 a.m.

KLA49284 Multiple vulnerabilities in Apple iTunes

2023-05-2300:00:00
Kaspersky Lab
threats.kaspersky.com
11
apple itunes
elevation of privilege
malicious users
privileges
update
cve-2023-32353
cve-2023-32351

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0

Percentile

9.0%

An elevation of privilege vulnerabilities were found in Apple iTunes. Malicious users can exploit these vulnerabilities to gain privileges.

Original advisories

About the security content of iTunes 12.12.9 for Windows

Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

Apple-iTunes

CVE list

CVE-2023-32353 critical

CVE-2023-32351 critical

CVE-2023-32430 unknown

Solution

Update to the latest version

Download iTunes

Impacts

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Apple iTunes earlier than 12.12.9

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0

Percentile

9.0%