Lucene search

K
vulnrichmentAppleVULNRICHMENT:CVE-2023-42974
HistoryMar 28, 2024 - 3:39 p.m.

CVE-2023-42974

2024-03-2815:39:11
apple
github.com
2
macos
ios
race condition
state handling
arbitrary code
kernel privileges

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "ipados",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "16.7",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "17.0",
        "lessThan": "17.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "macos",
    "versions": [
      {
        "status": "affected",
        "version": "12.0",
        "lessThan": "12.7",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "13.0",
        "lessThan": "13.6",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "14.0",
        "lessThan": "14.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-42974