Arbitrary Code Execution and Denial of Service in Apple Products
CVE-2018-4206
7.8HIGH
Summary
The vulnerability arises in the Crash Reporter component of various Apple platforms including iOS, macOS, tvOS, and watchOS. Attackers can exploit this vulnerability by using a specially crafted application to replace a privileged port name, which may lead to arbitrary code execution or cause a denial of service through memory corruption. It is crucial for users to update their systems to the latest versions to mitigate potential risks associated with this security flaw.
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved