Logic Issue in iTunes Software by Apple
CVE-2022-26773
7.1HIGH
Summary
A logic issue has been identified in Apple's iTunes software that can lead to unauthorized file deletions. Specifically, the application has been found to potentially allow for the deletion of files without having proper permissions. This situation arises from inadequate state management within the application. The issue has been addressed in iTunes version 12.12.4 for Windows, enhancing its security and protecting against potential exploitation.
Affected Version(s)
iTunes for Windows < 12.12
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved