CVE-2022-32794
In Apple macOS existieren mehrere Schwachstellen. Die Fehler bestehen in den Komponenten AMD, apache, AppKit, AppleAVD, AppleGraphicsControl, AppleScript, AVEVideoEncoder, Contacts, CoreTypes, CVMS, DriverKit, Graphics Drivers, ImageIO, Intel Graphics Drivers, IOKit, IOMobileFrameBuffer, Kernel, LaunchServices, libresolv, LibreSSL, libxml2, OpenSSL, PackageKit, Vorschau, Drucken, Safari Private Browsing, Sicherheit, SMB, SoftwareUpdate, Spotlight, TCC, Tcl, Vim, WebKit, WebRTC, Wi-Fi, zip, zlib und zsh. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen und im schlimmsten Fall das System zu kompromittieren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.05% · 15.9th percentile
Risk Scores
Exploit Intelligence
- CIRCL seen: CVE-2022-32794 (circl-sighting)
- https://support.apple.com/en-us/HT213255 (circl)
- https://support.apple.com/en-us/HT213256 (circl)
- https://support.apple.com/en-us/HT213257 (circl)
- https://github.com/acheong08/CVE-2022-26726-POC (certbund)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
…and 5 more exploits
Timeline
- May 16, 2022 CVE Published
- Nov 2, 2022 EPSS Score
- Dec 15, 2022 EPSS Score
- Jan 28, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 12, 2023 EPSS Score
- Apr 24, 2023 EPSS Score
- Jun 6, 2023 EPSS Score
- Jun 21, 2023 CVE Updated
- Jul 20, 2023 EPSS Score
- Sep 1, 2023 EPSS Score
- Oct 14, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-1057.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1057 advisory
- https://support.apple.com/en-us/HT213255 advisory
- https://support.apple.com/en-us/HT213256 advisory
- https://support.apple.com/en-us/HT213257 advisory
- https://github.com/acheong08/CVE-2022-26726-POC exploit
- https://www.cisa.gov/uscert/ncas/current-activity/2022/04/01/apple-releases-security-updates-0 advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html advisory
- https://wojciechregula.blog/post/macos-sandbox-escape-via-terminal/ advisory