First published: Sun Sep 25 2016(Updated: )
AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4696 is considered to have a medium severity due to the potential for arbitrary code execution in a privileged context.
To fix CVE-2016-4696, update to macOS 10.12 or later, which addresses the vulnerability.
CVE-2016-4696 affects Apple OS X versions up to and including 10.11.6.
CVE-2016-4696 allows attackers to execute arbitrary code or cause a denial of service through a crafted application.
There is no known workaround for CVE-2016-4696; updating to a secure version is necessary.