CVE-2015-7047: Input Validation
Published Dec 11, 2015
·Updated
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted mach message that is misparsed.
Affected Software
4 affected components
Apple WatchOS<=2.0
Apple tvOS<=9.0
Apple iPhone OS<=9.1
Apple iOS and macOS<=10.11.1
Event History
Dec 11, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7047?
CVE-2015-7047 is considered a high-severity vulnerability that allows local users to gain elevated privileges.
2
What systems are affected by CVE-2015-7047?
CVE-2015-7047 affects Apple iOS versions before 9.2, OS X versions before 10.11.2, tvOS before 9.1, and watchOS before 2.1.
3
How do I fix CVE-2015-7047?
To mitigate CVE-2015-7047, ensure that your systems are updated to the latest versions of iOS, OS X, tvOS, and watchOS.
4
How can local users exploit CVE-2015-7047?
Local users can exploit CVE-2015-7047 by sending a crafted mach message that the kernel misparses.
5
What kind of privilege escalation does CVE-2015-7047 enable?
CVE-2015-7047 allows local users to gain elevated privileges on the affected Apple operating systems.