VulnerabilityModified
CVE-2020-9858
Running the installer in an untrusted directory may result in arbitrary code execution.
HIGH 7.8EPSS 0.49%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Assistant 2.2.0.0 (v. 1A11). Running the installer in an untrusted directory may result in arbitrary code execution.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- apple/windows migration assistant
- Source
- product-security@apple.com
References
- https://support.apple.com/HT211186Vendor Advisory
- https://support.apple.com/HT211186Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.