CVE-2022-26774

Description

A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate their privileges.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.137

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-26751,CVE-2022-26711,CVE-2022-26774,CVE-2022-26773,CVE-2022-26717 are fixed in Apple iTunes (12.12.4.1)Windows
Vulnerabilities CVE-2022-26751,CVE-2022-26711,CVE-2022-26774,CVE-2022-26773,CVE-2022-26717 are fixed in Apple iTunes (X64) (12.12.4.1)Windows
Multiple vulnerabilities are fixed in Apple iTunes (X64) (12.12.4.1)Windows
Multiple vulnerabilities are fixed in Apple iTunes (12.12.4.1)Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 12.12.3Windows
Multiple Vulnerabilities are affected in Apple iTunes 12.12.3Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-324938Apple iTunes (12.12.4.1)
PATCH-324939Apple iTunes (X64) (12.12.4.1)
PATCH-334920Apple iTunes (X64) (12.13.1.3)
PATCH-334919Apple iTunes (12.13.1.3)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234