VulnerabilityAnalyzed
CVE-2020-9859
Apple Multiple Products Code Execution Vulnerability
KEVHIGH 7.8EPSS 0.83%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-415
- Affected
- apple/ipados · apple/iphone os · apple/mac os x · apple/tvos · apple/watchos
- Source
- product-security@apple.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-9859
References
- https://support.apple.com/HT211214Release Notes, Vendor Advisory
- https://support.apple.com/HT211214Release Notes, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9859US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.