VDB
CVE-2023-42842
CVE-2023-42842
PUBLISHED
CVSS 8.699999809265137 HIGH
Es bestehen mehrere Schwachstellen in Apple macOS. Diese Fehler bestehen in mehreren Komponenten wie Bluetooth, Find My, AppleGraphicsControl oder Kernel, unter anderem aufgrund mehrerer Sicherheitsprobleme wie unsachgemäße Speicherbehandlung oder unsachgemäße Prüfungen. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen. Einige der Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.
EPSS 0.04% · 13.0th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.04%
13.0th percentile
Exploit Intelligence
- campaign_operation_triangulation.yar (github-yara)
- campaign_operation_triangulation.yar (github-yara)
- campaign_operation_triangulation.yar (github-yara)
- campaign_operation_triangulation.yar (github-yara)
- campaign_operation_triangulation.yar (github-yara)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
- macos_v2_generated.go (github-poc)
…and 5 more exploits
Timeline
- Oct 25, 2023 CVE Published
- Oct 26, 2023 EPSS Score
- Nov 26, 2023 EPSS Score
- Dec 27, 2023 EPSS Score
- Jan 27, 2024 EPSS Score
- Feb 27, 2024 EPSS Score
- Mar 29, 2024 EPSS Score
- Apr 29, 2024 EPSS Score
- May 9, 2024 PoC Published
- May 30, 2024 EPSS Score
- Jun 29, 2024 EPSS Score
- Jul 30, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3094.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-3094 advisory
- https://support.apple.com/kb/HT214036 advisory
- https://support.apple.com/kb/HT214037 advisory
- https://support.apple.com/kb/HT214038 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2753.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2753 advisory
- https://support.apple.com/en-us/HT213983 advisory
- https://support.apple.com/en-us/HT213984 advisory
- https://support.apple.com/en-us/HT213985 advisory
- https://jhftss.github.io/CVE-2023-42942-xpcroleaccountd-Root-Privilege-Escalation/ advisory