CVE-2020-27950
high-risk
Published 2020-12-08
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.
Do I need to act?
!
36.6% chance of exploitation in next 30 days
EPSS score — higher than 63% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10
Medium
LOCAL
/ LOW complexity
Affected Vendors
References (21)
Third Party Advisory
http://packetstormsecurity.com/files/161296/XNU-Kernel-Mach-Message-Trailers-Mem...
Mailing List
http://seclists.org/fulldisclosure/2020/Dec/32
Vendor Advisory
https://support.apple.com/en-us/HT211928
Vendor Advisory
https://support.apple.com/en-us/HT211929
Vendor Advisory
https://support.apple.com/en-us/HT211931
Vendor Advisory
https://support.apple.com/en-us/HT211940
Vendor Advisory
https://support.apple.com/en-us/HT211944
Vendor Advisory
https://support.apple.com/en-us/HT211945
Vendor Advisory
https://support.apple.com/en-us/HT211946
Vendor Advisory
https://support.apple.com/en-us/HT211947
Third Party Advisory
http://packetstormsecurity.com/files/161296/XNU-Kernel-Mach-Message-Trailers-Mem...
Mailing List
http://seclists.org/fulldisclosure/2020/Dec/32
Vendor Advisory
https://support.apple.com/en-us/HT211928
Vendor Advisory
https://support.apple.com/en-us/HT211929
Vendor Advisory
https://support.apple.com/en-us/HT211931
Vendor Advisory
https://support.apple.com/en-us/HT211940
Vendor Advisory
https://support.apple.com/en-us/HT211944
Vendor Advisory
https://support.apple.com/en-us/HT211945
Vendor Advisory
https://support.apple.com/en-us/HT211946
Vendor Advisory
https://support.apple.com/en-us/HT211947
and 1 more references
51
/ 100
high-risk
Severity
18/34 · Moderate
Exploitability
23/34 · High
Exposure
10/34 · Low