9.8
CVSSv3

CVE-2017-2527

Published: 22/05/2017 Updated: 13/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in certain Apple products. macOS prior to 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remote malicious users to execute arbitrary code or cause a denial of service (memory consumption and application crash) via crafted data.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=1175 CAMediaTimingFunctionBuiltin is a class in QuartzCore Its initWithCoder: method reads an Int "index" then passes that to builtin_function mov ebx, edi <-- controlled unsigned int mov r14d, ebx lea r15, __ZL9functions_0 ; functions mov rax, [r15+r14* ...