Vulnerability Name: CVE-2022-26714 (CCN-226602) Assigned: 2022-05-16 Published: 2022-05-16 Updated: 2022-06-08 Summary: A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges. CVSS v3 Severity: 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-787 Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2022-26714 Source: XF Type: UNKNOWNapple-ios-cve202226714-priv-esc(226602) Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213253 Source: CCN Type: Apple security document HT213254About the security content of tvOS 15.5 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213254 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213255 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213256 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213257 Source: CCN Type: Apple security document HT213258About the security content of iOS 15.5 and iPadOS 15.5 Source: MISC Type: Release Notes, Vendor Advisoryhttps://support.apple.com/en-us/HT213258 Vulnerable Configuration: Configuration 1 :cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:* (Version < 10.15.7)OR cpe:/o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-002:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-003:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-004:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-005:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-006:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-008:*:*:*:*:*:* OR cpe:/o:apple:ipados:*:*:*:*:*:*:*:* (Version < 15.5) OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version < 15.5) OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2021-007:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2022-001:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2022-002:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2022-003:*:*:*:*:*:* OR cpe:/o:apple:macos:*:*:*:*:*:*:*:* (Version >= 11.0 and < 11.6.6) OR cpe:/o:apple:macos:*:*:*:*:*:*:*:* (Version >= 12.0 and < 12.4) OR cpe:/o:apple:watchos:*:*:*:*:*:*:*:* (Version < 8.6) Denotes that component is vulnerable BACK
apple mac os x *
apple mac os x 10.15.7 -
apple mac os x 10.15.7 security_update_2020-001
apple mac os x 10.15.7 security_update_2021-001
apple mac os x 10.15.7 security_update_2021-002
apple mac os x 10.15.7 security_update_2021-003
apple mac os x 10.15.7 security_update_2021-004
apple mac os x 10.15.7 security_update_2021-005
apple mac os x 10.15.7 security_update_2021-006
apple mac os x 10.15.7 security_update_2021-008
apple ipados *
apple iphone os *
apple mac os x 10.15.7 security_update_2021-007
apple mac os x 10.15.7 security_update_2022-001
apple mac os x 10.15.7 security_update_2022-002
apple mac os x 10.15.7 security_update_2022-003
apple macos *
apple macos *
apple watchos *