CVE-2020-27930
high-risk
Published 2020-12-08
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.
Do I need to act?
!
43.9% chance of exploitation in next 30 days
EPSS score — higher than 56% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Vendors
References (21)
Third Party Advisory
http://packetstormsecurity.com/files/161294/Apple-Safari-Remote-Code-Execution.h...
Mailing List
http://seclists.org/fulldisclosure/2020/Dec/32
Vendor Advisory
https://support.apple.com/en-us/HT211928
Vendor Advisory
https://support.apple.com/en-us/HT211929
Vendor Advisory
https://support.apple.com/en-us/HT211931
Vendor Advisory
https://support.apple.com/en-us/HT211940
Vendor Advisory
https://support.apple.com/en-us/HT211944
Vendor Advisory
https://support.apple.com/en-us/HT211945
Vendor Advisory
https://support.apple.com/en-us/HT211946
Vendor Advisory
https://support.apple.com/en-us/HT211947
Third Party Advisory
http://packetstormsecurity.com/files/161294/Apple-Safari-Remote-Code-Execution.h...
Mailing List
http://seclists.org/fulldisclosure/2020/Dec/32
Vendor Advisory
https://support.apple.com/en-us/HT211928
Vendor Advisory
https://support.apple.com/en-us/HT211929
Vendor Advisory
https://support.apple.com/en-us/HT211931
Vendor Advisory
https://support.apple.com/en-us/HT211940
Vendor Advisory
https://support.apple.com/en-us/HT211944
Vendor Advisory
https://support.apple.com/en-us/HT211945
Vendor Advisory
https://support.apple.com/en-us/HT211946
Vendor Advisory
https://support.apple.com/en-us/HT211947
and 1 more references
60
/ 100
high-risk
Severity
24/34 · High
Exploitability
24/34 · High
Exposure
12/34 · Low