SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-8817

coresymbolicationd in CoreSymbolication in Apple OS X before 10.10.2 does not verify that expected data types are present in XPC messages, which allows attackers to execute arbitrary code in a privileged context via a crafted app, as demonstrated by…

HIGH 10.0EPSS 2.89%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

coresymbolicationd in CoreSymbolication in Apple OS X before 10.10.2 does not verify that expected data types are present in XPC messages, which allows attackers to execute arbitrary code in a privileged context via a crafted app, as demonstrated by lack of verification of xpc_dictionary_get_value API return values during handling of a (1) match_mmap_archives, (2) delete_mmap_archives, (3) write_mmap_archive, or (4) read_mmap_archive command.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
2.89% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-19
Affected
apple/mac os x
Source
product-security@apple.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.