CVE-2015-1117: Medium severity iphone os vulnerability
The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 do not properly perform privilege drops, which makes it easier for attackers to execute code with unintended user or group privileges via a crafted app.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1117?
CVE-2015-1117 is considered a moderate severity vulnerability due to improper privilege drops in Apple's operating systems.
How do I fix CVE-2015-1117?
To fix CVE-2015-1117, upgrade your device to at least iOS 8.3, macOS 10.10.3, or tvOS 7.2.
Which software versions are affected by CVE-2015-1117?
CVE-2015-1117 affects Apple iOS versions prior to 8.3, macOS versions before 10.10.3, and tvOS versions before 7.2.
Can CVE-2015-1117 allow remote code execution?
Yes, CVE-2015-1117 can allow attackers to execute code with unintended user or group privileges.
What systems are impacted by CVE-2015-1117?
CVE-2015-1117 impacts iPhones, iPads, Macs, and Apple TVs running the affected software versions.