CVE-2017-2421: Race Condition
Published Apr 2, 2017
·Updated
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "AppleGraphicsPowerManagement" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
Affected Software
1 affected component
Apple iOS and macOS<=10.12.3
Event History
Apr 2, 2017
CVE Published
via MITRE·01:36 AM
Data Sourced
via MITRE·01:36 AM
Description
Data Sourced
via NVD·01:59 AM
DescriptionSeverityWeaknessAffected Software
Jun 17, 58461
Event
07:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-2421?
CVE-2017-2421 has been rated as a high-severity vulnerability due to its potential to allow arbitrary code execution in a privileged context.
2
How do I fix CVE-2017-2421?
To fix CVE-2017-2421, users should update their macOS to version 10.12.4 or later.
3
What products are affected by CVE-2017-2421?
CVE-2017-2421 affects certain Apple products running macOS versions prior to 10.12.4.
4
What is the cause of CVE-2017-2421?
CVE-2017-2421 is caused by a race condition in the AppleGraphicsPowerManagement component.
5
Can CVE-2017-2421 be exploited remotely?
CVE-2017-2421 requires local access to the affected system, making remote exploitation unlikely.