First published: Wed May 18 2022(Updated: )
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate their privileges.
Credit: Sai Wynn Myat @404death product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.12.4 | 12.12.4 |
Apple Itunes Windows | <12.12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this iTunes vulnerability is CVE-2022-26774.
The title of this vulnerability is "A logic issue was addressed with improved state management."
The severity of CVE-2022-26774 is high with a severity value of 7.8.
The vulnerability can be fixed by updating iTunes to version 12.12.4 for Windows.
iTunes for Windows users with versions up to but not including 12.12.4 are affected by this vulnerability.