CVE-2022-46706
In Apple macOS existieren mehrere Schwachstellen. Die Fehler bestehen in den Komponenten Accelerate Framework, AMD, AppKit, AppleGraphicsControl, AppleScript, BOM, Curl, FaceTime, ImageIO, Intel Graphics Driver, IOGPUFamily, Kernel, libarchive, Login Window, GarageBand MIDI, NSSpellChecker, PackageKit, Preferences, QuickTime Player, Safari Downloads, Sandbox, Siri, SMB, SoftwareUpdate, System Preferences, UIKit, Vim, VoiceOver, WebKit, Wi-Fi und Xar. Ein entfernter anonymer, authentisierter, lokaler oder physischer Angreifer kann diese Schwachstellen ausnutzen, um seine Privilegien zu erweitern, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, einen Spoofing-Angriff durchzuführen und beliebigen Code auszuführen. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.04% · 11.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Apple macOS Catalina |
Exploit Intelligence
- https://support.apple.com/en-us/HT213183 (circl)
- https://support.apple.com/en-us/HT213185 (circl)
- https://support.apple.com/en-us/HT213184 (circl)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v1_generated.go (github-poc)
- macos_v1_generated.go (github-poc)
…and 3 more exploits
Timeline
- Mar 14, 2022 CVE Published
- Jun 21, 2023 CVE Updated
- Aug 15, 2023 EPSS Score
- Sep 17, 2023 EPSS Score
- Oct 21, 2023 EPSS Score
- Nov 23, 2023 EPSS Score
- Dec 27, 2023 EPSS Score
- Jan 29, 2024 EPSS Score
- Mar 2, 2024 EPSS Score
- Apr 5, 2024 EPSS Score
- May 8, 2024 EPSS Score
- Jun 11, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-1056.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1056 advisory
- https://support.apple.com/en-us/HT213183 advisory
- https://support.apple.com/en-us/HT213184 advisory
- https://support.apple.com/en-us/HT213185 advisory
- https://www.trendmicro.com/en_us/research/22/d/macos-suhelper-root-privilege-escalation-vulnerability-a-deep-di.html advisory