VulnerabilityModified
CVE-2010-0532
Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.
MEDIUM 6.9EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- apple/itunes
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/39135Vendor Advisory
- http://support.apple.com/kb/HT4105
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7110
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/39135Vendor Advisory
- http://support.apple.com/kb/HT4105
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7110
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.