HIGH
An issue was discovered in certain Apple products
Published Dec 25, 2017
7.8
HIGHCVSS 3.0
EPSS 14.89%
Description
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://packetstormsecurity.com/files/153148/Safari-Webkit-Proxy-Object-Type-Confusion.html x_refsource_MISC
- http://www.securityfocus.com/bid/102134 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039952 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039953 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://support.apple.com/HT208325 x_refsource_CONFIRMVendor Advisory
- https://support.apple.com/HT208327 x_refsource_CONFIRMVendor Advisory
- https://support.apple.com/HT208334 x_refsource_CONFIRMVendor Advisory
- https://www.exploit-db.com/exploits/43320/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/153148/Safari-Webkit-Proxy-Object-Type-Confusion.html | x_refsource_MISC | |
| http://www.securityfocus.com/bid/102134 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1039952 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1039953 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://support.apple.com/HT208325 | x_refsource_CONFIRMVendor Advisory | |
| https://support.apple.com/HT208327 | x_refsource_CONFIRMVendor Advisory | |
| https://support.apple.com/HT208334 | x_refsource_CONFIRMVendor Advisory | |
| https://www.exploit-db.com/exploits/43320/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Dec 25, 2017
Updated Aug 5, 2024
Reserved Aug 30, 2017
Link CVE-2017-13861
CISA Vulnrichment
Updated n/a