VulnerabilityModified
CVE-2017-2361
The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.
MEDIUM 6.1EPSS 17.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 17.13% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apple/mac os x
- Source
- product-security@apple.com
References
- http://www.securityfocus.com/bid/95723Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037671
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1040
- https://support.apple.com/HT207483Vendor Advisory
- https://www.exploit-db.com/exploits/41443/
- http://www.securityfocus.com/bid/95723Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037671
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1040
- https://support.apple.com/HT207483Vendor Advisory
- https://www.exploit-db.com/exploits/41443/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.