CVE-2024-27793: Code Injection
CoreMedia. The issue was addressed with improved checks.
Other sources
The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or arbitrary code execution.
— MITRE
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2024-27793?
CVE-2024-27793 has a severity level indicating a potential for arbitrary code execution and unexpected app termination.
How do I fix CVE-2024-27793?
To fix CVE-2024-27793, upgrade to iTunes version 12.13.2 for Windows or later.
What product is affected by CVE-2024-27793?
CVE-2024-27793 affects iTunes for Windows prior to version 12.13.2.
What type of vulnerability is CVE-2024-27793?
CVE-2024-27793 is a vulnerability related to parsing files that can lead to arbitrary code execution.
Who resolved the issue in CVE-2024-27793?
The issue in CVE-2024-27793 was resolved by Apple with improved checks in the software.