PT-2020-20867 · Apple · Apple Macos

Published

2020-09-21

·

Updated

2021-07-21

·

CVE-2020-9921

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to 10.15.6
Description A memory corruption issue was addressed with improved memory handling. This issue allows a malicious application to execute arbitrary code with system privileges. The issue is related to Time-Of-Check Time-Of-Use Privilege Escalation Vulnerabilities in various Apple macOS processes, including process token TexSubImage2D, process token TexPBOUpload, process token CopyPixelsSrcFBO, and process token BlitFramebuffer.
Recommendations For macOS versions prior to 10.15.6, update to macOS Catalina 10.15.6 to resolve the issue. As a temporary workaround, consider restricting the execution of malicious applications to minimize the risk of exploitation.

Fix

Time Of Check To Time Of Use

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9921
ZDI-20-1210
ZDI-20-1211
ZDI-20-1212
ZDI-20-1213

Affected Products

Apple Macos