PT-2022-15539 · Apple · Apple Macos
Richard Warren
·
Published
2022-03-14
·
Updated
2023-03-07
·
CVE-2022-22582
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to Big Sur 11.6.5
macOS versions prior to Monterey 12.3
macOS Catalina (affected versions not specified, but fixed in Security Update 2022-003)
Description
A validation issue existed in the handling of symlinks, which has been addressed with improved validation of symlinks. This could allow a local user to write arbitrary files.
Recommendations
For macOS Catalina, apply Security Update 2022-003 to resolve the issue.
For macOS Big Sur, update to version 11.6.5 or later to resolve the issue.
For macOS Monterey, update to version 12.3 or later to resolve the issue.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos