935
VMScore

CVE-2017-13875

Published: 25/12/2017 Updated: 28/12/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in certain Apple products. macOS prior to 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows malicious users to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

Exploits

/* Source: bugschromiumorg/p/project-zero/issues/detail?id=1375 AppleIntelCapriController::GetLinkConfig trusts a user-supplied value in the structure input which it uses to index a small table of pointers without bounds checking The OOB-read pointer is passed to AppleIntelFramebuffer::validateDisplayMode which will read a pointer to a ...

Recent Articles

Apple gets around to patching all the other High Sierra security holes
The Register • Shaun Nichols in San Francisco • 07 Dec 2017

Another week, another Mac patch to install

Apple has released a security update to address nearly two dozen vulnerabilities in macOS High Sierra. The update comes little more than a week after Apple had to kick out an emergency fix to close up a glaring hole in macOS that allowed anyone with access to a Mac (either in person or remote) to bypass the login screen and act as a root account. This week's High Sierra update, numbered 10.13.2, addresses a total of 22 CVE-listed flaws in various components of the macOS operating system. Eight o...