CVE-2020-3837
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple Multiple Products Memory Corruption Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 14% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-787
מוצרים מושפעים
apple: ipados; apple: iphone os; apple: mac os x; apple: tvos; apple: watchos
קישורים
- https://support.apple.com/HT210918 Release NotesVendor Advisory
- https://support.apple.com/HT210919 Release NotesVendor Advisory
- https://support.apple.com/HT210920 Release NotesVendor Advisory
- https://support.apple.com/HT210921 Release NotesVendor Advisory
- https://support.apple.com/HT210918 Release NotesVendor Advisory
- https://support.apple.com/HT210919 Release NotesVendor Advisory
- https://support.apple.com/HT210920 Release NotesVendor Advisory
- https://support.apple.com/HT210921 Release NotesVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource