CVE-2009-2794: Race Condition
The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2794?
CVE-2009-2794 is considered a medium severity vulnerability due to its potential to allow unauthorized access to Exchange mail accounts.
How do I fix CVE-2009-2794?
To fix CVE-2009-2794, update your Apple iPhone OS to version 3.1 or later.
What does CVE-2009-2794 affect?
CVE-2009-2794 affects Apple iPhone OS versions prior to 3.1 and some versions of iPod touch.
What is the exploit method for CVE-2009-2794?
CVE-2009-2794 can be exploited locally by bypassing the Maximum inactivity time lock feature.
Who is impacted by CVE-2009-2794?
Local users of affected iPhone and iPod touch devices may be impacted by CVE-2009-2794.