ZDI-CAN-16895: ZDI-23-1497: Apple iTunes Incorrect Permission Assignment Privilege Escalation Vulnerability
Published Oct 4, 2023
·Updated
This vulnerability allows local attackers to escalate privileges on affected installations of Apple iTunes. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2022-26773.
Affected Software
1 affected component
Apple iTunes
Event History
Oct 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-16895?
The severity of ZDI-CAN-16895 is rated at 7.8 on the CVSS scale.
2
How do I fix ZDI-CAN-16895?
To fix ZDI-CAN-16895, update Apple iTunes to the latest version provided by Apple.
3
Who is affected by ZDI-CAN-16895?
ZDI-CAN-16895 affects installations of Apple iTunes on Windows.
4
What types of attacks does ZDI-CAN-16895 enable?
ZDI-CAN-16895 enables local attackers to escalate privileges on affected systems.
5
What are the prerequisites for exploiting ZDI-CAN-16895?
An attacker must first have the ability to execute low-privileged code on the target system to exploit ZDI-CAN-16895.