TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-30869

HIGHCISA KEV
7.8

Description

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.

Details CVE

Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie8/24/2021
Derniere modification10/23/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurApple
ProduitiOS, iPadOS, and macOS
Nom vulnerabiliteApple iOS, iPadOS, and macOS Type Confusion Vulnerability
Date ajout KEV2021-11-03
Date limite remediation2021-11-17
Utilise dans ransomwareUnknown

Produits affectes

apple:ipadosapple:iphone_osapple:mac_os_xapple:macos

Faiblesses (CWE)

CWE-843CWE-843

References

https://support.apple.com/en-us/HT212146(product-security@apple.com)
https://support.apple.com/en-us/HT212147(product-security@apple.com)
https://support.apple.com/en-us/HT212824(product-security@apple.com)
https://support.apple.com/en-us/HT212825(product-security@apple.com)
https://support.apple.com/en-us/HT212146(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212147(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212824(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212825(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.