VulnerabilityModified
CVE-2021-30892
A malicious application may be able to modify protected parts of the file system.
MEDIUM 5.5EPSS 10.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.4%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to modify protected parts of the file system.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 10.35% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- apple/mac os x · apple/macos
- Source
- product-security@apple.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.