PT-2022-21476 · Apple · Apple Macos

Co0Py_Cat

+3

·

Published

2022-07-20

·

Updated

2023-05-17

·

CVE-2022-32797

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apple macOS versions prior to macOS Big Sur 11.6.8 Apple macOS versions prior to macOS Monterey 12.5 Apple macOS Catalina version with Security Update 2022-005
Description The issue concerns the processing of maliciously crafted AppleScript binaries, which may lead to unexpected termination or disclosure of process memory. This is related to untrusted pointer dereference and out-of-bounds read issues in AppleScript binary parsing.
Recommendations For macOS Catalina, apply Security Update 2022-005 to resolve the issue. For macOS Big Sur, update to version 11.6.8 or later to resolve the issue. For macOS Monterey, update to version 12.5 or later to resolve the issue.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-32797
ZDI-22-1130
ZDI-23-645

Affected Products

Apple Macos