Vulnerability Name: CVE-2022-22593 (CCN-218140) Assigned: 2022-01-26 Published: 2022-01-26 Updated: 2022-03-26 Summary: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. A malicious application may be able to execute arbitrary code with kernel privileges. CVSS v3 Severity: 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-120 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2022-22593 Source: XF Type: UNKNOWNapple-watchos-cve202222593-bo(218140) Source: CCN Type: Apple security document HT213053About the security content of iOS 15.3 and iPadOS 15.3 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213053 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213054 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213055 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213056 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213057 Source: CCN Type: Apple security document HT213059About the security content of watchOS 8.4 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213059 Vulnerable Configuration: Configuration 1 :cpe:/o:apple:ipados:*:*:*:*:*:*:*:* (Version < 15.3)OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version < 15.3) OR cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:* (Version < 10.15.7) OR cpe:/o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2020:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2020-005:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2020-007:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-002:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-003:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-006:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-007:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-008:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2022-001:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2022-002:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:supplemental_update:*:*:*:*:*:* OR cpe:/o:apple:macos:*:*:*:*:*:*:*:* (Version >= 11.0 and < 11.6.3) OR cpe:/o:apple:macos:*:*:*:*:*:*:*:* (Version >= 12.0.0 and < 12.2) OR cpe:/o:apple:tvos:*:*:*:*:*:*:*:* (Version < 15.3) OR cpe:/o:apple:watchos:*:*:*:*:*:*:*:* (Version < 8.4) Denotes that component is vulnerable BACK
apple ipados *
apple iphone os *
apple mac os x *
apple mac os x 10.15.7 -
apple mac os x 10.15.7 security_update_2020
apple mac os x 10.15.7 security_update_2020-001
apple mac os x 10.15.7 security_update_2020-005
apple mac os x 10.15.7 security_update_2020-007
apple mac os x 10.15.7 security_update_2021-001
apple mac os x 10.15.7 security_update_2021-002
apple mac os x 10.15.7 security_update_2021-003
apple mac os x 10.15.7 security_update_2021-006
apple mac os x 10.15.7 security_update_2021-007
apple mac os x 10.15.7 security_update_2021-008
apple mac os x 10.15.7 security_update_2022-001
apple mac os x 10.15.7 security_update_2022-002
apple mac os x 10.15.7 supplemental_update
apple macos *
apple macos *
apple tvos *
apple watchos *