CVE-2019-8662
CVE-2019-8662
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 9.8%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
30 Jul 2019Public PoC
18 Dec 2019Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.
public PoCs found — 2
exploitdbwww.exploit-db.com/exploits/47608unverifiedexploitdbwww.exploit-db.com/exploits/47189unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →