Vulnerability Name: | CVE-2022-26704 (CCN-226684) | ||||||||||||
Assigned: | 2022-05-16 | ||||||||||||
Published: | 2022-05-16 | ||||||||||||
Updated: | 2022-11-10 | ||||||||||||
Summary: | A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.4. An app may be able to gain elevated privileges. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-59 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-26704 Source: FULLDISC Type: Mailing List, Third Party Advisory 20220721 APPLE-SA-2022-07-20-3 macOS Big Sur 11.6.8 Source: FULLDISC Type: Mailing List, Third Party Advisory 20220721 APPLE-SA-2022-07-20-4 Security Update 2022-005 Catalina Source: XF Type: UNKNOWN apple-macos-cve202226704-priv-esc(226684) Source: MISC Type: Technical Description, Third Party Advisory https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0032/MNDT-2022-0032.md Source: CCN Type: Apple security document HT213257 About the security content of macOS Monterey 12.4 Source: MISC Type: Release Notes, Vendor Advisory https://support.apple.com/en-us/HT213257 Source: CCN Type: Apple security document HT213343 About the security content of Security Update 2022-005 Catalina Source: CCN Type: Apple security document HT213344 About the security content of macOS Big Sur 11.6.8 Source: CONFIRM Type: Mailing List https://support.apple.com/kb/HT213343 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/kb/HT213344 | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |