Remote Code Execution Vulnerability in Apple QuickTime
CVE-2015-7085

6.6MEDIUM

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
9 January 2016

Summary

A critical vulnerability exists in Apple QuickTime versions prior to 7.7.9, enabling remote attackers to execute arbitrary code or induce a denial of service. This risk is triggered when the application processes specially crafted movie files, leading to memory corruption and potential application crashes. Addressing this vulnerability is essential for maintaining security against exploit attempts targeting unpatched installations.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.