CVE-2017-2425: Double Free
Published Apr 2, 2017
·Updated
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "SecurityFoundation" component. A double free vulnerability allows remote attackers to execute arbitrary code via a crafted certificate.
Affected Software
1 affected component
Apple iOS and macOS<=10.12.3
Event History
Apr 2, 2017
CVE Published
via MITRE·01:36 AM
Data Sourced
via MITRE·01:36 AM
Description
Data Sourced
via NVD·01:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-2425?
CVE-2017-2425 has a high severity due to its potential for remote code execution.
2
How do I fix CVE-2017-2425?
To fix CVE-2017-2425, update your macOS to version 10.12.4 or later.
3
What component is affected by CVE-2017-2425?
CVE-2017-2425 affects the SecurityFoundation component in macOS.
4
What products are impacted by CVE-2017-2425?
CVE-2017-2425 impacts macOS versions prior to 10.12.4.
5
Can CVE-2017-2425 be exploited remotely?
Yes, CVE-2017-2425 can be exploited remotely via a crafted certificate.