Multiple vulnerabilities in Apple macOS Ventura



Published: 2023-01-23
Risk High
Patch available YES
Number of vulnerabilities 26
CVE-ID CVE-2023-23508
CVE-2023-23517
CVE-2023-23518
CVE-2023-23511
CVE-2022-3705
CVE-2023-23505
CVE-2023-23497
CVE-2023-23499
CVE-2023-23504
CVE-2023-23502
CVE-2023-23507
CVE-2023-23493
CVE-2023-23513
CVE-2022-35260
CVE-2022-32221
CVE-2022-42916
CVE-2022-42915
CVE-2023-23519
CVE-2023-23500
CVE-2023-23506
CVE-2023-23498
CVE-2023-23503
CVE-2023-23510
CVE-2023-23512
CVE-2023-23496
CVE-2023-23501
CWE-ID CWE-254
CWE-119
CWE-416
CWE-200
CWE-269
CWE-284
CWE-125
CWE-121
CWE-440
CWE-319
CWE-415
CWE-20
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
macOS
Operating systems & Components / Operating system

Vendor Apple Inc.

Security Bulletin

This security bulletin contains information about 26 vulnerabilities.

1) Security features bypass

EUVDB-ID: #VU71438

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23508

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows a local application to bypass certain security restrictions.

The vulnerability exists due to an error within Windows Installer. A local application can bypass Privacy preferences.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

2) Buffer overflow

EUVDB-ID: #VU71437

Risk: High

CVSSv3.1:

CVE-ID: CVE-2023-23517

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in WebKit. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

3) Buffer overflow

EUVDB-ID: #VU71436

Risk: High

CVSSv3.1:

CVE-ID: CVE-2023-23518

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in WebKit. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

4) Security features bypass

EUVDB-ID: #VU71443

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23511

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows a local application to bypass implemented security restrictions.

The vulnerability exists due to an error within the Weather application. A local application can bypass Privacy preferences.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

5) Use-after-free

EUVDB-ID: #VU68962

Risk: High

CVSSv3.1:

CVE-ID: CVE-2022-3705

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when handling files within the qf_update_buffer() function in quickfix.c. A remote attacker can trick the victim to open a specially crafted file, trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

6) Information disclosure

EUVDB-ID: #VU71435

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23505

CWE-ID: CWE-200 - Information Exposure

Exploit availability: No

Description

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a privacy issue in Screen Time. A local application can gain unauthorized access to user's contact information.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

7) Improper Privilege Management

EUVDB-ID: #VU71434

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23497

CWE-ID: CWE-269 - Improper Privilege Management

Exploit availability: No

Description

The vulnerability allows a local application to escalate privileges.

The vulnerability exists due to improper privilege management in PackageKit. A local application can execute arbitrary code with root privileges.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

8) Improper access control

EUVDB-ID: #VU71432

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23499

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in AppleMobileFileIntegrity. A local application can gain access to sensitive user information.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

9) Buffer overflow

EUVDB-ID: #VU71441

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23504

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error within the OS kernel. A local application can trigger memory corruption and execute arbitrary code with kernel privileges.


Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

10) Out-of-bounds read

EUVDB-ID: #VU71442

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23502

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the OS kernel. A local application can trigger an out-of-bounds read error and read contents of memory on the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

11) Buffer overflow

EUVDB-ID: #VU71440

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23507

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error within Intel Graphics Driver. A local application can trigger memory corruption and execute arbitrary code with kernel privileges.


Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

12) Security features bypass

EUVDB-ID: #VU71439

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23493

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a logic error within DiskArbitration, related to mounting of an encryptoed volume. An encrypted volume may be unmounted and remounted by a different user without prompting for the password.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

13) Buffer overflow

EUVDB-ID: #VU71433

Risk: High

CVSSv3.1:

CVE-ID: CVE-2023-23513

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in dcerpc when mounting a malicious SMB share. A remote attacker can trick the victim to mount a malicious SMB share, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

14) Stack-based buffer overflow

EUVDB-ID: #VU68747

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-35260

CWE-ID: CWE-121 - Stack-based buffer overflow

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when parsing .netrc file. A local user can pass a specially crafted file to the curl, trigger a stack-based buffer overflow and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

15) Expected behavior violation

EUVDB-ID: #VU68746

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2022-32221

CWE-ID: CWE-440 - Expected Behavior Violation

Exploit availability: No

Description

The vulnerability allows a remote attacker to force unexpected application behavior.

The vulnerability exists due to a logic error for a reused handle when processing subsequent HTTP PUT and POST requests. The libcurl can erroneously use the read callback (CURLOPT_READFUNCTION) to ask for data to send, even when the CURLOPT_POSTFIELDS option has been set, if the same handle previously was used to issue a PUT request, which used that callback. As a result, such behavior can influence application flow and force unpredictable outcome.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

16) Cleartext transmission of sensitive information

EUVDB-ID: #VU68749

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2022-42916

CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error when parsing URL with IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. A remote attacker can bypass curl's HSTS check and trick it into using unencrypted HTTP protocol.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

17) Double Free

EUVDB-ID: #VU68748

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2022-42915

CWE-ID: CWE-415 - Double Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing non-200 proxy HTTP responses for the following schemes: dict, gopher, gophers, ldap, ldaps, rtmp, rtmps, telnet. A remote attacker can trigger a double free error by forcing the application into connecting to resources that are not allowed by the configured proxy.


Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

18) Input validation error

EUVDB-ID: #VU71444

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23519

CWE-ID: CWE-20 - Improper Input Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in ImageIO. A remote attacker can trick the victim to open a specially crafted file and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

19) Out-of-bounds read

EUVDB-ID: #VU71445

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23500

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the OS kernel. A local application can trigger an out-of-bounds read error and read contents of memory on the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

20) Improper Privilege Management

EUVDB-ID: #VU71446

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23506

CWE-ID: CWE-269 - Improper Privilege Management

Exploit availability: No

Description

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper privilege management in libxpc. A local application can gain access to sensitive user information.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

21) Information disclosure

EUVDB-ID: #VU71447

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23498

CWE-ID: CWE-200 - Information Exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an error in Mail Drafts implementation when forwarding emails. The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account and lead to information disclosure.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

22) Information disclosure

EUVDB-ID: #VU71448

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23503

CWE-ID: CWE-200 - Information Exposure

Exploit availability: No

Description

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a logic issue in Maps application. A local application can bypass Privacy preferences.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

23) Improper access control

EUVDB-ID: #VU71449

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23510

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions. A local application can gain access to user’s Safari history.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

24) Input validation error

EUVDB-ID: #VU71450

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-23512

CWE-ID: CWE-20 - Improper Input Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient handling of cache in Safari. A remote attacker can trick the victim into visiting a website and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

25) Buffer overflow

EUVDB-ID: #VU71451

Risk: High

CVSSv3.1:

CVE-ID: CVE-2023-23496

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in WebKit. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

26) Out-of-bounds read

EUVDB-ID: #VU71452

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23501

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a boundary error within the Wi-Fi component. A local application trigger an out-of-bounds read and read kernel memory.

Mitigation

Install update from vendor's website.

Vulnerable software versions

macOS: 13.0 22A380 - 13.1 22C65


CPE2.3 External links

http://support.apple.com/en-us/HT213605

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###