CVE-2014-1347

Description

Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.

Risk Information

Base Score
7.1
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.133

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Apple iTunes (X64) 11.2Windows
Multiple vulnerabilities affected in Apple iTunes 11.2Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 11.0.2Windows
Multiple Vulnerabilities are affected in Apple iTunes 11.0.2Windows
Multiple Vulnerabilities are affected in Apple iTunes For Mac 11.0.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 11.1.3Mac
Vulnerabilities CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0Mac
Vulnerabilities CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0.1Mac
Vulnerabilities CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0.3Mac
Vulnerabilities CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0.4Mac
Vulnerabilities CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0.5Mac
Vulnerabilities CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.1Mac
Vulnerabilities CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.1.1Mac
Vulnerabilities CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.1.2Mac
Vulnerabilities CVE-2014-1347 are affected in Apple iTunes For Mac 11.1.4Mac
Vulnerabilities CVE-2014-1347 are affected in Apple iTunes For Mac 11.1.5Mac
Vulnerabilities CVE-2014-1347 are affected in Apple iTunes For Mac 11.2Mac
Vulnerabilities CVE-2013-1035,CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0Mac
Vulnerabilities CVE-2013-1035,CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0.1Mac
Vulnerabilities CVE-2013-1035,CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0.3Mac
Vulnerabilities CVE-2013-1035,CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0.4Mac
Vulnerabilities CVE-2013-1035,CVE-2014-1242,CVE-2014-1347 are affected in Apple iTunes For Mac 11.0.5Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342817Apple iTunes (X64) (12.13.4.4)
PATCH-342816Apple iTunes (12.13.4.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234