PT-2021-7573 · Apple · Apple Macos

Mickey Jin

+1

·

Published

2021-09-13

·

Updated

2022-02-22

·

CVE-2021-30832

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to Security Update 2021-005 Catalina macOS Big Sur versions prior to 11.6
Description The issue is related to a memory corruption problem, specifically a use-after-free privilege escalation vulnerability in the XPC CVMServer service of Mac OS. This vulnerability can be exploited by a local attacker to elevate their privileges. The vulnerability is caused by a buffer overflow operation.
Recommendations For macOS versions prior to Security Update 2021-005 Catalina, apply Security Update 2021-005. For macOS Big Sur versions prior to 11.6, update to macOS Big Sur 11.6. As a temporary workaround, consider restricting access to the CVMServer service until a patch is available.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00096
CVE-2021-30832
ZDI-22-355

Affected Products

Apple Macos