VDB
CVE-2022-42858
CVE-2022-42858
PUBLISHED
In Apple macOS existieren mehrere Schwachstellen aufgrund verschiedener Fehler in der Speicherverwaltung, sowie aufgrund fehlender oder mangelhafter Prüfungen. Betroffen sind zahlreiche Komponenten, beispielsweise WebKit und der Kernel von macOS. Ein Angreifer kann dadurch den Nutzer täuschen, Informationen offenlegen, Sicherheitsmechanismen umgehen, seine Privilegien eskalieren und beliebigen Code mit Kernel-Rechten ausführen.
EPSS 0.16% · 37.4th percentile
Risk Scores
EPSS Score
0.16%
37.4th percentile
Exploit Intelligence
- https://www.cisa.gov/news-events/alerts/2024/01/31/cisa-adds-one-known-exploited-vulnerability-catalog (certbund)
- CIRCL seen: CVE-2022-42858 (circl-sighting)
- CIRCL seen: CVE-2022-42858 (circl-sighting)
- https://support.apple.com/en-us/HT213532 (circl)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v1_generated.go (github-poc)
…and 4 more exploits
Timeline
- Dec 13, 2022 CVE Published
- Apr 10, 2023 PoC Published
- Apr 11, 2023 EPSS Score
- Apr 14, 2023 CVE Updated
- May 19, 2023 EPSS Score
- Jun 26, 2023 EPSS Score
- Aug 2, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Oct 17, 2023 EPSS Score
- Nov 24, 2023 EPSS Score
- Dec 31, 2023 EPSS Score
- Feb 7, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-2313.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-2313 advisory
- https://support.apple.com/de-de/HT213532 advisory
- https://support.apple.com/de-de/HT213533 advisory
- https://support.apple.com/de-de/HT213534 advisory
- https://www.cisa.gov/news-events/alerts/2024/01/31/cisa-adds-one-known-exploited-vulnerability-catalog exploit