CVE-2017-2422: Buffer Overflow
Published Apr 2, 2017
·Updated
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Multi-Touch" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Affected Software
1 affected component
Apple iOS and macOS<=10.12.3
Event History
Apr 2, 2017
CVE Published
via MITRE·01:36 AM
Data Sourced
via MITRE·01:36 AM
Description
Data Sourced
via NVD·01:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-2422?
CVE-2017-2422 is classified with high severity due to its potential for executing arbitrary code in a privileged context.
2
How do I fix CVE-2017-2422?
To fix CVE-2017-2422, users should update to macOS version 10.12.4 or later.
3
What types of attacks does CVE-2017-2422 enable?
CVE-2017-2422 allows attackers to execute arbitrary code or cause denial of service through memory corruption.
4
Which Apple products are affected by CVE-2017-2422?
CVE-2017-2422 affects certain Apple products running macOS before version 10.12.4.
5
What component is involved in CVE-2017-2422?
The vulnerability involves the 'Multi-Touch' component in affected versions of macOS.