The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Accounts | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Amd | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Applemobilefileintegrity | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Bluetooth | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Bootcamp | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Coreservices | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Curl | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Driverkit | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Dyld | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Icloudphotolibrary | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Imageio | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Iohidfamily | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Iomobileframebuffer | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Itunesstore | — | — | Oct 14, 2024 | Dec 15, 2022 |
| Apple Osx Kernel | — | Upgrade macOS to the latest version | Jan 10, 2023 | Dec 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub