PT-2022-18073 · Apple · Itunes

404Death

+1

·

Published

2022-05-26

·

Updated

2025-05-30

·

CVE-2022-26773

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apple iTunes versions prior to 12.12.4 for Windows
Description A logic issue was addressed with improved state management, allowing an application to potentially delete files for which it does not have permission.
Recommendations For Apple iTunes versions prior to 12.12.4 for Windows, update to version 12.12.4 or later to resolve the issue.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-26773
ZDI-23-1497

Affected Products

Itunes