CVE-2023-32351: High severity apple iTunes for Windows vulnerability
Published May 23, 2023
·Updated
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges.
Other sources
iTunes. A logic issue was addressed with improved checks.
— Apple
Credit
ycdxsb@@IIE(VARAS), Zeeshan Shaikh – Synopsys Cybersecurity Research Center (CyRC)@@bugzzzhunter, James Tsz Ko Yeung@@5cript1diot
Affected Software
2 affected componentsFixes available
apple iTunes for Windows<12.12.9
12.12.9
apple Itunes Windows<12.12.9
Event History
May 23, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Weakness
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-32351?
The severity of CVE-2023-32351 is high with a CVSS score of 7.8.
2
How can an app gain elevated privileges in iTunes?
An app can gain elevated privileges in iTunes through a logic issue that was addressed in iTunes 12.12.9 for Windows.
3
Is iTunes 12.12.9 for Windows affected by CVE-2023-32351?
No, iTunes 12.12.9 for Windows is not affected by CVE-2023-32351 as the issue is fixed in this version.
4
Which version of iTunes for Windows fixes CVE-2023-32351?
CVE-2023-32351 is fixed in iTunes version 12.12.9 for Windows.
5
Where can I find more information about CVE-2023-32351?
You can find more information about CVE-2023-32351 at the following reference link: [https://support.apple.com/en-us/HT213763]