Apple Security Advisories · May 2018 — Apple Security Advisories
3 advisories 3 CVEs

Apple-vendor CVEs for 2018-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-8897

OtherWeaponized exploitCRITICAL2018-05-08

A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that ar...

CVEs:CVE-2018-8897

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2017-17688

OtherEPSS <= 49%CRITICAL2018-05-14

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification De...

CVEs:CVE-2017-17688

Affected products

ProductStatusVendorPackageEcosystem
mail affected apple
Upstream advisory

CVE-2017-17689

OtherEPSS <= 49%MEDIUM2018-05-14

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVEs:CVE-2017-17689

Affected products

ProductStatusVendorPackageEcosystem
mail affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.