ID:10791 - Exploit for UNIX symbolic link following in Apple iOS and iPadOS - CVE-2024-44258

 
Main Vulnerability Database Exploits ID:10791 - Exploit for UNIX symbolic link following in Apple iOS and iPadOS - CVE-2024-44258

ID:10791 - Exploit for UNIX symbolic link following in Apple iOS and iPadOS - CVE-2024-44258

Published: November 4, 2024


Vulnerability identifier: #VU99422
Vulnerability risk: Medium
CVE-ID: CVE-2024-44258
CWE-ID: CWE-61
Exploitation vector: Remote access
Vulnerable software:
Apple iOS
iPadOS

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a symlink following issue in Managed Configuration. A remote attacker can trick the victim into using a malicious backup file, modify protected system files and compromise the affected system.


Remediation

Install updates from vendor's website.