PT-2017-17446 · Apple · Apple Macos

Published

2017-05-18

·

Updated

2019-10-03

·

CVE-2017-6990

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 10.12.5
Description The issue involves the HFS component and allows attackers to bypass intended memory-read restrictions via a crafted app. This can lead to an uninitialized memory information disclosure privilege escalation.
Recommendations For macOS versions prior to 10.12.5, update to version 10.12.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the HFS component until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-6990
ZDI-17-352

Affected Products

Apple Macos