CVE-2019-8602
moderate-risk
Published 2019-12-18
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to elevate privileges.
Do I need to act?
~
4.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Vendors
References (16)
Vendor Advisory
https://support.apple.com/HT210118
Vendor Advisory
https://support.apple.com/HT210119
Vendor Advisory
https://support.apple.com/HT210120
Vendor Advisory
https://support.apple.com/HT210122
Vendor Advisory
https://support.apple.com/HT210124
Vendor Advisory
https://support.apple.com/HT210125
Vendor Advisory
https://support.apple.com/HT210212
Vendor Advisory
https://support.apple.com/HT210118
Vendor Advisory
https://support.apple.com/HT210119
Vendor Advisory
https://support.apple.com/HT210120
Vendor Advisory
https://support.apple.com/HT210122
Vendor Advisory
https://support.apple.com/HT210124
Vendor Advisory
https://support.apple.com/HT210125
Vendor Advisory
https://support.apple.com/HT210212
45
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
7/34 · Low
Exposure
14/34 · Moderate