PT-2022-15539 · Apple · Apple Macos

Richard Warren

·

Published

2022-03-14

·

Updated

2023-03-07

·

CVE-2022-22582

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to Big Sur 11.6.5 macOS versions prior to Monterey 12.3 macOS Catalina (affected versions not specified, but fixed in Security Update 2022-003)
Description A validation issue existed in the handling of symlinks, which has been addressed with improved validation of symlinks. This could allow a local user to write arbitrary files.
Recommendations For macOS Catalina, apply Security Update 2022-003 to resolve the issue. For macOS Big Sur, update to version 11.6.5 or later to resolve the issue. For macOS Monterey, update to version 12.3 or later to resolve the issue.

Exploit

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2022-22582

Affected Products

Apple Macos