6.9
CVSSv2

CVE-2015-1117

Published: 10/04/2015 Updated: 08/03/2019
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS prior to 8.3, Apple OS X prior to 10.10.3, and Apple TV prior to 7.2 do not properly perform privilege drops, which makes it easier for malicious users to execute code with unintended user or group privileges via a crafted app.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple tvos

apple mac os x