Lucene search

K
kasperskyKaspersky LabKLA65186
HistoryDec 14, 2023 - 12:00 a.m.

KLA65186 PE vulnerability in Apple iTunes

2023-12-1400:00:00
Kaspersky Lab
threats.kaspersky.com
4
apple itunes
elevation of privilege
vulnerability
update
12.13.1

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.0%

An elevation of privilege vulnerability was found in Apple iTunes. Malicious users can exploit this vulnerability to gain privileges.

Original advisories

About the security content of iTunes 12.13.1 for Windows

Related products

Apple-iTunes

CVE list

CVE-2023-42938 unknown

Solution

Update to the latest version

Download iTunes

Impacts

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Apple iTunes earlier than 12.13.1

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.0%