First published: Fri Apr 10 2015(Updated: )
The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 do not properly perform privilege drops, which makes it easier for attackers to execute code with unintended user or group privileges via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iOS | <=8.2 | |
tvOS | <=7.1 | |
Apple iOS and macOS | <=10.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1117 is considered a moderate severity vulnerability due to improper privilege drops in Apple's operating systems.
To fix CVE-2015-1117, upgrade your device to at least iOS 8.3, macOS 10.10.3, or tvOS 7.2.
CVE-2015-1117 affects Apple iOS versions prior to 8.3, macOS versions before 10.10.3, and tvOS versions before 7.2.
Yes, CVE-2015-1117 can allow attackers to execute code with unintended user or group privileges.
CVE-2015-1117 impacts iPhones, iPads, Macs, and Apple TVs running the affected software versions.