CVE-2021-30847

Description

This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.402

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-30835,CVE-2021-30847,CVE-2021-30849 are fixed in Apple iTunes (X64) (12.12.0.6)Windows
Vulnerabilities CVE-2021-30835,CVE-2021-30847,CVE-2021-30849 are fixed in Apple iTunes (12.12.0.6)Windows
Multiple vulnerabilities fixed in Apple iTunes (X64) (12.12.1.1)Windows
Multiple vulnerabilities fixed in Apple iTunes (X64) (12.12.2.2)Windows
Multiple vulnerabilities fixed in Apple iTunes (12.12.1.1)Windows
Multiple vulnerabilities fixed in Apple iTunes (12.12.2.2)Windows
Vulnerabilities CVE-2021-30835,CVE-2021-30847,CVE-2021-30849 are affected in Apple iTunes (X64) 12.11Windows
Vulnerabilities CVE-2021-30835,CVE-2021-30847,CVE-2021-30849 are affected in Apple iTunes 12.11Windows
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6.8 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6.6 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6.5 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6.3 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6.2 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6.1 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6.4 - Software UpdateMac
Multiple vulnerabilities are fixed in MacOS Big Sur 11.6.7 - Software UpdateMac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 12.11.3Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-321486Apple iTunes (X64) (12.12.0.6)
PATCH-321485Apple iTunes (12.12.0.6)
PATCH-321560Apple iTunes (X64) (12.12.1.1)
PATCH-322191Apple iTunes (X64) (12.12.2.2)
PATCH-321559Apple iTunes (12.12.1.1)
PATCH-322190Apple iTunes (12.12.2.2)
PATCH-605753MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605753MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605753MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605753MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605752MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605752MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605752MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605753MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)
PATCH-605753MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234