CVE-2019-8577
CVE-2019-8577
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 10.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
18 Dec 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. An application may be able to gain elevated privileges.
Affected products
Apple · iCloud for WindowsApple · iOSApple · iTunes for WindowsApple · macOSApple · tvOSApple · watchOSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://research.checkpoint.com/2019/select-code_execution-from-using-sqlite/https://support.apple.com/HT210118https://support.apple.com/HT210119https://support.apple.com/HT210120https://support.apple.com/HT210122https://support.apple.com/HT210124https://support.apple.com/HT210125https://support.apple.com/HT210212