Logic Issue in iTunes Software by Apple
CVE-2022-26773

7.1HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
26 May 2022

Summary

A logic issue has been identified in Apple's iTunes software that can lead to unauthorized file deletions. Specifically, the application has been found to potentially allow for the deletion of files without having proper permissions. This situation arises from inadequate state management within the application. The issue has been addressed in iTunes version 12.12.4 for Windows, enhancing its security and protecting against potential exploitation.

Affected Version(s)

iTunes for Windows < 12.12

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.