First published: Tue Oct 29 2019(Updated: )
A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
Credit: Hou JingYi @hjy79425575 Qihoo 360 CERTHou JingYi @hjy79425575 Qihoo 360 CERT product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.10.2 | 12.10.2 |
Apple macOS Catalina | <10.15.1 | 10.15.1 |
Apple Itunes Windows | <12.10.2 | |
Apple Mac OS X | <10.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID of this issue is CVE-2019-8801.
The severity level of CVE-2019-8801 is high with a CVSS score of 7.8.
CVE-2019-8801 affects iTunes for Windows versions up to and excluding 12.10.2, macOS Catalina versions up to and excluding 10.15.1.
To fix the vulnerability in iTunes for Windows, update to version 12.10.2 or newer.
To fix the vulnerability in macOS Catalina, update to version 10.15.1 or newer.