CVE-2021-30860
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple Multiple Products Integer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 76% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-190
מוצרים מושפעים
apple: ipados; apple: iphone os; apple: mac os x; apple: macos; apple: watchos; xpdfreader: xpdf; freedesktop: poppler
קישורים
- https://support.apple.com/en-us/HT212804 Vendor Advisory
- https://support.apple.com/en-us/HT212805 Vendor Advisory
- https://support.apple.com/en-us/HT212806 Vendor Advisory
- https://support.apple.com/en-us/HT212807 Vendor Advisory
- https://support.apple.com/kb/HT212824 Vendor Advisory
- https://support.apple.com/en-us/HT212804 Vendor Advisory
- https://support.apple.com/en-us/HT212805 Vendor Advisory
- https://support.apple.com/en-us/HT212806 Vendor Advisory
- https://support.apple.com/en-us/HT212807 Vendor Advisory
- https://support.apple.com/kb/HT212824 Vendor Advisory