VulnerabilityModified
CVE-2019-8805
An application may be able to execute arbitrary code with system privileges.
HIGH 7.8EPSS 2.57%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.57% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x
- Source
- product-security@apple.com
References
- https://support.apple.com/HT210722Vendor Advisory
- https://support.apple.com/HT210722Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.