SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-1320

IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes…

MEDIUM 4.9EPSS 0.37%

Does this matter?

Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.

Description

IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.

CVSS 2.0
4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
EPSS
0.37% probability · 30th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
apple/mac os x · apple/iphone os · apple/tvos
Source
product-security@apple.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.