CVE-2013-0981
The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 accesses pipe object pointers that originated in userspace, which allows local users to gain privileges via crafted code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 accesses pipe object pointers that originated in userspace, which allows local users to gain privileges via crafted code.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- apple/iphone os · apple/tvos
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.htmlVendor Advisory
- http://support.apple.com/kb/HT5702Vendor Advisory
- http://support.apple.com/kb/HT5704Vendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.htmlVendor Advisory
- http://support.apple.com/kb/HT5702Vendor Advisory
- http://support.apple.com/kb/HT5704Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.