CVE-2022-48683
In Apple macOS existieren mehrere Schwachstellen. Diese sind auf Fehler in den Komponenten "Accelerate Framework", "Apple Neural Engine", "AppleAVD", "AppleMobileFileIntegrity", "ATS", "Audio", "AVEVideoEncoder", "Calendar", "CFNetwork", "ColorSync", "Crash Reporter", "curl", "Directory Utility", "DriverKit", "Exchange", "Find My", "Finder", "GPU Drivers", "Grapher", "Image Processing", "ImageIO", "Intel Graphics Driver", "IOHIDFamily", "IOKit", "Kernel", "Mail", "Maps", MediaLibrary", "ncurses", "Notes", "Notifications", "PackageKit", "Photos", "ppp", "Ruby", "Sandbox", "Security", "Shortcuts", "Sidecar", "Siri", "SMB", "Software Update", "SQLite", "Vim", "Weather", "WebKit", "WebKit PDF" sowie "WebKit Sandboxing". Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, beliebigen Programmcode auszuführen, seine Privilegien zu erweitern, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder sonstige Auswirkungen zu verursachen. Zur erfolgreichen Ausnutzung ist eine Benutzeraktion erforderlich.
EPSS 0.11% · 29.6th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Apple macOS Ventura_13 | |
| Apple | Apple macOS Monterey 12.6.1 | |
| Apple | Apple macOS Big Sur 11.7.1 |
Exploit Intelligence
- https://support.apple.com/en-us/HT213488 (circl)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v1_generated.go (github-poc)
- macos_v1_generated.go (github-poc)
- macos_v1_generated.go (github-poc)
- macos_v1_generated.go (github-poc)
…and 1 more exploits
Timeline
- Oct 24, 2022 CVE Published
- Jun 11, 2024 EPSS Score
- Jul 4, 2024 EPSS Score
- Jul 27, 2024 EPSS Score
- Aug 19, 2024 EPSS Score
- Sep 11, 2024 EPSS Score
- Oct 4, 2024 EPSS Score
- Oct 27, 2024 EPSS Score
- Nov 19, 2024 EPSS Score
- Nov 21, 2024 CVE Updated
- Dec 13, 2024 EPSS Score
- Jan 5, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-1846.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1846 advisory
- https://support.apple.com/en-us/HT213488 advisory
- https://support.apple.com/en-us/HT213493 advisory
- https://support.apple.com/en-us/HT213494 advisory