PT-2020-16833 · Apple · Itunes
Sourav Newatia
·
Published
2020-12-08
·
Updated
2021-07-21
·
CVE-2020-27895
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iTunes versions prior to 12.11 for Windows
Description
An information disclosure issue existed in the transition of program state, which could allow a malicious application to access local users' Apple IDs. This issue was addressed with improved state handling.
Recommendations
For versions prior to 12.11, update to iTunes 12.11 for Windows to resolve the issue. As a temporary workaround, consider restricting access to sensitive user information until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Itunes