9.3
CVSSv2

CVE-2017-2353

Published: 20/02/2017 Updated: 02/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in certain Apple products. macOS prior to 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows malicious users to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

Exploits

/* Source: bugschromiumorg/p/project-zero/issues/detail?id=973 IOService::matchPassive is called when trying to match a request dictionary against a candidate IOService We can call this function on a controlled IOService with a controlled matching table OSDictionary via the io_service_match_property_table_* kernel MIG APIs wrapped by IO ...