← Retour aux CVEs
CVE-2024-23225
HIGHCISA KEV7.8
Description
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.
Details CVE
Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie3/5/2024
Derniere modification4/3/2026
Sourcekev
Observations honeypot0
CISA KEV
FournisseurApple
ProduitMultiple Products
Nom vulnerabiliteApple Multiple Products Memory Corruption Vulnerability
Date ajout KEV2024-03-06
Date limite remediation2024-03-27
Utilise dans ransomwareUnknown
Produits affectes
apple:ipadosapple:iphone_osapple:macosapple:tvosapple:visionosapple:watchos
Faiblesses (CWE)
CWE-787
References
https://support.apple.com/en-us/120880(product-security@apple.com)
https://support.apple.com/en-us/120881(product-security@apple.com)
https://support.apple.com/en-us/120882(product-security@apple.com)
https://support.apple.com/en-us/120883(product-security@apple.com)
https://support.apple.com/en-us/120884(product-security@apple.com)
https://support.apple.com/en-us/120886(product-security@apple.com)
https://support.apple.com/en-us/120893(product-security@apple.com)
https://support.apple.com/en-us/120895(product-security@apple.com)
http://seclists.org/fulldisclosure/2024/Mar/18(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Mar/19(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Mar/21(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Mar/22(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Mar/23(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Mar/24(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Mar/25(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2024/Mar/26(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT214081(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT214082(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT214082(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT214083(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT214084(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT214085(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT214086(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT214087(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT214088(af854a3a-2127-422b-91ae-364da2661108)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23225(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.