Remote Code Execution in Apple QuickTime Allows Exploitation via Malicious Movie Files
CVE-2015-7089
6.6MEDIUM
Summary
Apple QuickTime versions prior to 7.7.9 are susceptible to a remote code execution vulnerability that allows attackers to execute arbitrary code or trigger a denial of service condition. This vulnerability is facilitated through the opening of crafted movie files, which can lead to memory corruption and application crashes, posing significant risks to users who may inadvertently engage with malicious media content. It is crucial for individuals and organizations to update to the latest version to mitigate these threats.
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved