CVE-2021-30905
CVE-2021-30905
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Aug 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina. Processing a maliciously crafted file may disclose user information.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://support.apple.com/en-us/HT212867https://support.apple.com/en-us/HT212869https://support.apple.com/en-us/HT212871https://support.apple.com/en-us/HT212874https://support.apple.com/en-us/HT212876https://support.apple.com/kb/HT212807https://support.apple.com/kb/HT212872https://www.zerodayinitiative.com/advisories/ZDI-21-1368/