TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2024-44308

HIGHCISA KEV
8.8

Beschreibung

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

CVE Details

CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht11/20/2024
Zuletzt geandert4/3/2026
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerApple
ProduktMultiple Products
SchwachstellennameApple Multiple Products Code Execution Vulnerability
KEV Aufnahmedatum2024-11-21
Behebungsfrist2024-12-12
Ransomware-NutzungUnknown

Betroffene Produkte

apple:ipadosapple:iphone_osapple:macosapple:safariapple:visionosdebian:debian_linux

Referenzen

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.