PT-2020-16833 · Apple · Itunes

Sourav Newatia

·

Published

2020-12-08

·

Updated

2021-07-21

·

CVE-2020-27895

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions iTunes versions prior to 12.11 for Windows
Description An information disclosure issue existed in the transition of program state, which could allow a malicious application to access local users' Apple IDs. This issue was addressed with improved state handling.
Recommendations For versions prior to 12.11, update to iTunes 12.11 for Windows to resolve the issue. As a temporary workaround, consider restricting access to sensitive user information until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-27895

Affected Products

Itunes