CVE-2019-8844
high-risk
Published 2020-10-27
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
Do I need to act?
~
3.0% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Products (10)
References (14)
Release Notes
https://support.apple.com/en-us/HT210785
Release Notes
https://support.apple.com/en-us/HT210789
Release Notes
https://support.apple.com/en-us/HT210790
Release Notes
https://support.apple.com/en-us/HT210792
Release Notes
https://support.apple.com/en-us/HT210793
Release Notes
https://support.apple.com/en-us/HT210794
Release Notes
https://support.apple.com/en-us/HT210795
Release Notes
https://support.apple.com/en-us/HT210785
Release Notes
https://support.apple.com/en-us/HT210789
Release Notes
https://support.apple.com/en-us/HT210790
Release Notes
https://support.apple.com/en-us/HT210792
Release Notes
https://support.apple.com/en-us/HT210793
Release Notes
https://support.apple.com/en-us/HT210794
Release Notes
https://support.apple.com/en-us/HT210795
52
/ 100
high-risk
Severity
30/34 · Critical
Exploitability
6/34 · Minimal
Exposure
16/34 · Moderate