CVE-2014-4461: Input Validation
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4461?
CVE-2014-4461 is considered a critical vulnerability allowing attackers to execute arbitrary code in a privileged context.
How do I fix CVE-2014-4461?
To mitigate CVE-2014-4461, users should upgrade to iOS 8.1.1, macOS 10.10.2, or the latest version of tvOS.
Which devices are affected by CVE-2014-4461?
CVE-2014-4461 affects Apple devices running iOS before 8.1.1, macOS before 10.10.2, and tvOS before 7.0.2.
What impact does CVE-2014-4461 have on system security?
CVE-2014-4461 can lead to unauthorized access and control over affected devices, posing significant security risks.
Is there a workaround for CVE-2014-4461?
No, the only effective resolution for CVE-2014-4461 is updating the affected software to the specified patched versions.