First published: Fri May 20 2016(Updated: )
Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <=12.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1742 is classified as a high-severity vulnerability allowing local users to gain elevated privileges.
To fix CVE-2016-1742, users should upgrade to Apple iTunes version 12.4 or later.
CVE-2016-1742 is caused by an untrusted search path vulnerability in the installer of Apple iTunes.
CVE-2016-1742 affects local users of Apple iTunes versions prior to 12.4.
No, CVE-2016-1742 requires local access to exploit the vulnerability.