First published: Tue Sep 19 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Credit: Alex Plaskett MWR InfoSecurityAlex Plaskett MWR InfoSecurityAlex Plaskett MWR InfoSecurityAlex Plaskett MWR InfoSecurity product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=10.3.3 | |
Apple Mac OS X | <=10.12.6 | |
Apple tvOS | <=10.2.2 | |
Apple watchOS | <=3.2.3 | |
Apple iOS | <11 | 11 |
Apple tvOS | <11 | 11 |
Apple watchOS | <4 | 4 |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2017-7114 is critical, with a CVSS score of 7.8.
This vulnerability affects iOS versions before 11, macOS versions before 10.13, tvOS versions before 11, and watchOS versions before 4.
Yes, attackers can execute arbitrary code with CVE-2017-7114 in a privileged context.
The remedy for CVE-2017-7114 is to update to iOS 11 (or higher), macOS High Sierra 10.13 (or higher), tvOS 11 (or higher), or watchOS 4 (or higher).
More information about CVE-2017-7114 can be found at the following references: [1] [2] [3].