CVE-2020-9966

high

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.

References

https://support.apple.com/en-us/HT211931

https://support.apple.com/en-us/HT211850

https://support.apple.com/en-us/HT211844

https://support.apple.com/en-us/HT211843

http://seclists.org/fulldisclosure/2020/Dec/32

Details

Source: Mitre, NVD

Published: 2020-12-08

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High