PT-2022-21476 · Apple · Apple Macos
Co0Py_Cat
+3
·
Published
2022-07-20
·
Updated
2023-05-17
·
CVE-2022-32797
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apple macOS versions prior to macOS Big Sur 11.6.8
Apple macOS versions prior to macOS Monterey 12.5
Apple macOS Catalina version with Security Update 2022-005
Description
The issue concerns the processing of maliciously crafted AppleScript binaries, which may lead to unexpected termination or disclosure of process memory. This is related to untrusted pointer dereference and out-of-bounds read issues in AppleScript binary parsing.
Recommendations
For macOS Catalina, apply Security Update 2022-005 to resolve the issue.
For macOS Big Sur, update to version 11.6.8 or later to resolve the issue.
For macOS Monterey, update to version 12.5 or later to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos