First published: Tue Sep 19 2017(Updated: )
Exchange ActiveSync. A validation issue existed in AutoDiscover V1. This was addressed by requiring TLS for AutoDiscover V1. AutoDiscover V2 is now supported.
Credit: Ilya Nesterov Maxim Goncharov product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=10.3.3 | |
Apple iOS | <11 | 11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7088 is a vulnerability that affects certain Apple products running iOS before version 11. It is a validation issue in AutoDiscover V1, specifically in the Exchange ActiveSync component.
CVE-2017-7088 allows remote attackers to erase a device by hijacking a cleartext AutoDiscover V1 session during the setup of an Exchange account.
Apple iPhone devices running iOS version up to and including 10.3.3, and devices running Apple iOS up to but not including version 11 are affected.
CVE-2017-7088 has a severity rating of high, with a score of 5.9.
To mitigate CVE-2017-7088, it is recommended to update your Apple device to iOS version 11 or newer.