ZDI-23-1497: Apple iTunes Incorrect Permission Assignment Privilege Escalation Vulnerability
Published Oct 4, 2023
·Updated
This vulnerability allows local attackers to escalate privileges on affected installations of Apple iTunes. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2022-26773.
Affected Software
1 affected component
Apple iTunes
Event History
Oct 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1497?
ZDI-23-1497 has a CVSS rating of 7.8, indicating high severity.
2
How do I fix ZDI-23-1497?
To fix ZDI-23-1497, update Apple iTunes to the latest version provided by Apple.
3
Who is affected by ZDI-23-1497?
Users of Apple iTunes for Windows are affected by ZDI-23-1497.
4
What type of attack is related to ZDI-23-1497?
ZDI-23-1497 is associated with local privilege escalation attacks.
5
What must an attacker do to exploit ZDI-23-1497?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-23-1497.