CVE-2019-8602
CVE-2019-8602
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 10.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
18 Dec 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to elevate privileges.
Affected products
Apple · iCloud for WindowsApple · iOSApple · iTunes for WindowsApple · macOSApple · tvOSApple · watchOSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://research.checkpoint.com/2019/select-code_execution-from-using-sqlite/https://support.apple.com/HT210118https://support.apple.com/HT210119https://support.apple.com/HT210120https://support.apple.com/HT210122https://support.apple.com/HT210124https://support.apple.com/HT210125https://support.apple.com/HT210212