VulnerabilityModified
CVE-2018-4147
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.
CRITICAL 9.8EPSS 1.54%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- apple/safari · apple/iphone os · apple/icloud · apple/itunes
- Source
- product-security@apple.com
References
- https://support.apple.com/HT208463Vendor Advisory
- https://support.apple.com/HT208465Vendor Advisory
- https://support.apple.com/HT208473Vendor Advisory
- https://support.apple.com/HT208474Vendor Advisory
- https://support.apple.com/HT208475Vendor Advisory
- https://support.apple.com/HT208463Vendor Advisory
- https://support.apple.com/HT208465Vendor Advisory
- https://support.apple.com/HT208473Vendor Advisory
- https://support.apple.com/HT208474Vendor Advisory
- https://support.apple.com/HT208475Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.