First published: Sat Dec 02 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CoreAnimation" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Credit: 360 Security Trend Micro Tencent Keen Security Lab @keen_lab Trend Micro360 Security Trend Micro Tencent Keen Security Lab @keen_lab Trend Micro360 Security Trend Micro Tencent Keen Security Lab @keen_lab Trend Micro360 Security Trend Micro Tencent Keen Security Lab @keen_lab Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <11.2 | |
Apple Mac OS X | <10.13.2 | |
Apple tvOS | <11.2 | |
Apple watchOS | <4.2 | |
Apple iOS | <11.2 | 11.2 |
Apple macOS High Sierra | <10.13.2 | 10.13.2 |
Apple Sierra | ||
Apple El Capitan | ||
Apple tvOS | <11.2 | 11.2 |
Apple watchOS | <4.2 | 4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7171 is a memory corruption issue in certain Apple products, including iOS, macOS, tvOS, and watchOS.
The severity of CVE-2017-7171 is critical with a CVSS score of 7.8.
CVE-2017-7171 affects iOS versions up to 11.2, macOS versions up to 10.13.2, tvOS versions up to 11.2, and watchOS versions up to 4.2.
CVE-2017-7171 allows attackers to execute arbitrary code in a privileged context.
To fix CVE-2017-7171, users should update their Apple devices to the latest available version of iOS, macOS, tvOS, or watchOS.