Lucene search

K
nvd[email protected]NVD:CVE-2022-32844
HistoryFeb 27, 2023 - 8:15 p.m.

CVE-2022-32844

2023-02-2720:15:11
CWE-362
web.nvd.nist.gov
2
cve-2022-32844
pointer authentication bypass
arbitrary kernel access

6.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.9%

A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication.

Affected configurations

NVD
Node
appleipadosRange<15.6
OR
appleiphone_osRange<15.6
OR
appletvosRange<15.6
OR
applewatchosRange<8.7

6.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.9%

Related for NVD:CVE-2022-32844