First published: Sat Dec 02 2017(Updated: )
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
Credit: Samuel Groß @5aelo Samuel Groß @5aelo Samuel Groß @5aelo Samuel Groß @5aelo product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <11.2 | |
Apple Mac OS X | >=10.11<10.11.6 | |
Apple Mac OS X | >=10.12<10.12.6 | |
Apple Mac OS X | =10.11.6 | |
Apple Mac OS X | =10.11.6-security_update_2016-001 | |
Apple Mac OS X | =10.11.6-security_update_2016-002 | |
Apple Mac OS X | =10.11.6-security_update_2016-003 | |
Apple Mac OS X | =10.11.6-security_update_2017-001 | |
Apple Mac OS X | =10.11.6-security_update_2017-002 | |
Apple Mac OS X | =10.11.6-security_update_2017-003 | |
Apple Mac OS X | =10.11.6-security_update_2017-004 | |
Apple Mac OS X | =10.12.6 | |
Apple Mac OS X | =10.12.6-security_update_2017-001 | |
Apple macOS | <10.13.2 | |
Apple tvOS | <11.2 | |
Apple watchOS | <4.2 | |
Apple iOS | <11.2 | 11.2 |
Apple macOS High Sierra | <10.13.2 | 10.13.2 |
Apple Sierra | ||
Apple El Capitan | ||
Apple watchOS | <4.2 | 4.2 |
Apple tvOS | <11.2 | 11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-13905 is a vulnerability in Apple products that allows an application to gain elevated privileges due to a race condition.
CVE-2017-13905 has a severity rating of 8.1, which is considered high.
CVE-2017-13905 affects macOS High Sierra 10.13.2, iOS 11.2, tvOS 11.2, watchOS 4.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan.
An application can exploit CVE-2017-13905 by leveraging the race condition to gain elevated privileges.
To fix CVE-2017-13905, update your Apple products to the respective fixed versions: tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, Security Update 2017-005 El Capitan, and watchOS 4.2.