828
VMScore

CVE-2021-30681

Published: 08/09/2021 Updated: 20/09/2021
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to gain root privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple ipados

apple iphone os

apple mac os x

apple mac os x 10.14.6

apple mac os x 10.15.7

apple macos

apple watchos

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-1 iOS 146 and iPadOS 146 iOS 146 and iPadOS 146 addresses the following issues Information about the security content is also available at supportapplecom/HT212528 Audio Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th gen ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-6 watchOS 75 watchOS 75 addresses the following issues Information about the security content is also available at supportapplecom/HT212533 Audio Available for: Apple Watch Series 3 and later Impact: Processing a maliciously crafted audio file may lead to arbitrary ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-2 macOS Big Sur 114 macOS Big Sur 114 addresses the following issues Information about the security content is also available at supportapplecom/HT212529 AMD Available for: macOS Big Sur Impact: A remote attacker may be able to cause unexpected application terminat ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-4 Security Update 2021-003 Catalina Security Update 2021-003 Catalina addresses the following issues Information about the security content is also available at supportapplecom/HT212530 AMD Available for: macOS Catalina Impact: A local user may be able to cause unexp ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-3 Security Update 2021-004 Mojave Security Update 2021-004 Mojave addresses the following issues Information about the security content is also available at supportapplecom/HT212531 AMD Available for: macOS Mojave Impact: A local user may be able to cause unexpected ...