CVE-2024-44193: High severity apple iTunes for Windows vulnerability
Published Sep 12, 2024
·Updated
A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privileges.
Other sources
iTunes. A logic issue was addressed with improved restrictions.
— Apple
Credit
Mads Ball, Bocheng Xiang with Fudan University, Willy R. Vasquez(The University of Texas at Austin), Srikanth Narayanaraju
Affected Software
2 affected componentsFixes available
apple iTunes for Windows<12.13.3
12.13.3
apple Itunes Windows<12.13.3
Event History
Oct 2, 2024
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-44193?
CVE-2024-44193 has been rated as a moderate severity vulnerability.
2
How do I fix CVE-2024-44193?
To fix CVE-2024-44193, update iTunes to version 12.13.3 or later for Windows.
3
What type of attack does CVE-2024-44193 enable?
CVE-2024-44193 allows a local attacker to elevate their privileges on the affected system.
4
In which software is CVE-2024-44193 found?
CVE-2024-44193 is found in iTunes for Windows, specifically versions prior to 12.13.3.
5
What did Apple do to address CVE-2024-44193?
Apple addressed CVE-2024-44193 by implementing improved restrictions in iTunes version 12.13.3.