Remote Code Execution Vulnerability in QuickTime by Apple
CVE-2015-7091
6.6MEDIUM
Summary
Apple QuickTime versions prior to 7.7.9 are susceptible to a vulnerability that allows remote attackers to execute arbitrary code. This attack vector is facilitated through specially crafted movie files, which can lead to memory corruption and application crashes. It is crucial for users to update their QuickTime installations to mitigate these security risks.
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved