First published: Tue Nov 17 2020(Updated: )
An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTunes 12.11 for Windows. A malicious application may be able to access local users Apple IDs.
Credit: Sourav Newatia (linkedin.com/in/sourav-newatia-5b0848a8/) product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.11 | 12.11 |
Apple Itunes Windows | <12.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2020-27895.
The title of this vulnerability is 'Windows Security. An information disclosure issue existed in the transition of program state.'
The software affected by this vulnerability is Apple iTunes for Windows version 12.11.
The severity of this vulnerability is not specified.
To fix this vulnerability, update Apple iTunes for Windows to version 12.11 or later.