CVE-2014-4386: Race Condition
Published Sep 18, 2014
·Updated
Race condition in the App Installation feature in Apple iOS before 8 allows local users to gain privileges and install unverified apps by leveraging /tmp write access.
Affected Software
10 affected components
apple iPhone OS<=7.1.2
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
apple iPhone OS=7.0.6
apple iPhone OS=7.1
apple iPhone OS=7.1.1
Event History
Sep 18, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4386?
CVE-2014-4386 is considered a high-severity vulnerability due to its potential to allow privilege escalation and the installation of unverified apps.
2
How do I fix CVE-2014-4386?
To fix CVE-2014-4386, upgrade your Apple iOS device to version 8.0 or later.
3
Who is affected by CVE-2014-4386?
CVE-2014-4386 affects local users of Apple iOS versions prior to 8.0, specifically those running versions up to 7.1.2.
4
What type of vulnerability is CVE-2014-4386?
CVE-2014-4386 is a race condition vulnerability found in the App Installation feature of Apple iOS.
5
Can CVE-2014-4386 be exploited remotely?
CVE-2014-4386 cannot be exploited remotely; it requires local access to the device to take advantage of the vulnerability.