CVE-2024-27815
Es bestehen mehrere Schwachstellen in Apple iOS und Apple iPadOS. Diese Fehler bestehen in verschiedenen Komponenten wie dem AppleAVD, dem Kernel oder dem Libsystem, u. a. aufgrund mehrerer sicherheitsrelevanter Probleme wie einer unsachgemäßen Speicherbehandlung und Rechteverwaltung oder einer unzureichenden Validierung von Benutzereingaben und mehr. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen, seine Privilegien zu erweitern oder vertrauliche Informationen offenzulegen. Einige der Schwachstellen erfordern eine Benutzerinteraktion für eine erfolgreiche Ausnutzung. .
EPSS 24.65% · 96.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Apple macOS <14.5 | |
| Apple | Apple iOS <16.7.8 | |
| Apple | Apple iPadOS <16.7.8 | |
| Apple | Apple macOS <12.7.5 | |
| Apple | Apple macOS <13.6.7 |
Exploit Intelligence
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc-repo)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc-repo)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc-repo)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc-repo)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc-repo)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc-repo)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc)
- macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3) (github-poc)
…and 27 more exploits
Timeline
- May 13, 2024 CVE Published
- Jun 11, 2024 EPSS Score
- Jul 27, 2024 EPSS Score
- Aug 19, 2024 EPSS Score
- Oct 4, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 27, 2024 EPSS Score
- Dec 13, 2024 EPSS Score
- Jan 5, 2025 EPSS Score
- Feb 20, 2025 EPSS Score
- Mar 15, 2025 EPSS Score
- Mar 20, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1097.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1097 advisory
- https://support.apple.com/en-us/HT214100 advisory
- https://support.apple.com/en-us/HT214101 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1109.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1109 advisory
- https://support.apple.com/en-us/HT214105 advisory
- https://support.apple.com/en-us/HT214106 advisory
- https://support.apple.com/en-us/HT214107 advisory
- https://github.com/wangtielei/POCs/blob/main/CVE-2024-27842/poc.m exploit