First published: Wed May 18 2022(Updated: )
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete files for which it does not have permission.
Credit: Sai Wynn Myat @404death product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.12.4 | 12.12.4 |
Apple Itunes Windows | <12.12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2022-26773.
The affected software is iTunes for Windows version up to but not including 12.12.4.
The severity of CVE-2022-26773 has not been disclosed.
To fix CVE-2022-26773, update iTunes for Windows to version 12.12.4 or later.
You can find more information about CVE-2022-26773 on the Apple support page at: https://support.apple.com/en-us/HT213259.