Уязвимость удалённого выполнения произвольного кода в компоненте WebKit ряда продуктов Apple из-за состояния гонки
Описание
Уязвимость в компонентах WebKit позволяет злоумышленнику выполнить произвольный код на устройстве, обратившись к специально созданному веб-сайту. Данная уязвимость возникает из-за состояния гонки в системе.
Затронутые версии ПО
- iOS версий до 11.4
- Safari версий до 11.1.1
- iCloud для Windows версий до 7.5
- iTunes для Windows версий до 12.7.5
- tvOS версий до 11.4
- watchOS версий до 4.3.1
Тип уязвимости
Удаленное выполнение кода
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Одно из
Одновременно
Одновременно
EPSS
7.5 High
CVSS3
5.1 Medium
CVSS2
Дефекты
Связанные уязвимости
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition.
An issue was discovered in certain Apple products. iOS before 11.4 is ...
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages a race condition.
EPSS
7.5 High
CVSS3
5.1 Medium
CVSS2