7.8

CVE-2022-42840

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 15.7.2
Apple ≫ iPadOS Version >= 16.0 < 16.2
Apple ≫ iPhone OS Version < 15.7.2
Apple ≫ iPhone OS Version >= 16.0 < 16.2
Apple ≫ macOS Version >= 11.0 < 11.7.2
Apple ≫ macOS Version >= 12.0.0 < 12.6.2
Apple ≫ macOS Version 13.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.288
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://seclists.org/fulldisclosure/2022/Dec/23
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/21
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/24
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/25
Third Party Advisory
Mailing List
https://support.apple.com/en-us/HT213532
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213533
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213534
Vendor Advisory
Release Notes
http://seclists.org/fulldisclosure/2022/Dec/20
Third Party Advisory
Mailing List
https://support.apple.com/en-us/HT213530
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213531
Vendor Advisory
Release Notes