CVE-2020-9965

high

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.

References

http://seclists.org/fulldisclosure/2020/Dec/32

https://support.apple.com/en-us/HT211843

https://support.apple.com/en-us/HT211844

https://support.apple.com/en-us/HT211850

https://support.apple.com/en-us/HT211931

Details

Source: MITRE

Published: 2020-12-08

Updated: 2021-03-11

Type: CWE-125

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH