Risk | High |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-22675 |
CWE-ID | CWE-787 |
Exploitation vector | Local |
Public exploit | This vulnerability is being exploited in the wild. |
Vulnerable software Subscribe |
iPadOS Operating systems & Components / Operating system Apple iOS Operating systems & Components / Operating system |
Vendor | Apple Inc. |
This security bulletin contains one high risk vulnerability.
EUVDB-ID: #VU61773
Risk: High
CVSSv3.1:
CVE-ID: CVE-2022-22675
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
Description The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the AppleAVD subsystem. A local user can run a specially crafted program to trigger an out-of-bounds write and execute arbitrary code with kernel privileges.
Note, the vulnerability is being actively exploited in the wild.
Install update from vendor's website.
Vulnerable software versionsiPadOS: 15.0 19A346 - 15.4 19E241
Apple iOS: 15.0 19A346 - 15.4 19E241
http://support.apple.com/en-us/HT213219
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?