VulnerabilityModified
CVE-2017-13782
It allows attackers to bypass intended memory-read restrictions via a /dev/dtracehelper attack involving the dtrace_dif_variable and dtrace_getarg functions.
MEDIUM 5.5EPSS 1.11%
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a /dev/dtracehelper attack involving the dtrace_dif_variable and dtrace_getarg functions.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/mac os x
- Source
- product-security@apple.com
References
- http://packetstormsecurity.com/files/172827/Apple-XNU-Kernel-Memory-Exposure.html
- http://www.securitytracker.com/id/1039710Third Party Advisory, VDB Entry
- https://lgtm.com/blog/apple_xnu_dtrace_CVE-2017-13782Technical Description, Third Party Advisory
- https://support.apple.com/HT208221Vendor Advisory
- http://packetstormsecurity.com/files/172827/Apple-XNU-Kernel-Memory-Exposure.html
- http://www.securitytracker.com/id/1039710Third Party Advisory, VDB Entry
- https://lgtm.com/blog/apple_xnu_dtrace_CVE-2017-13782Technical Description, Third Party Advisory
- https://support.apple.com/HT208221Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.