Main
Vulnerability Database
Exploits
ID:10791 - Exploit for UNIX symbolic link following in Apple iOS and iPadOS - CVE-2024-44258
ID:10791 - Exploit for UNIX symbolic link following in Apple iOS and iPadOS - CVE-2024-44258
Published: November 4, 2024
Vulnerability identifier: #VU99422
Vulnerability risk: Medium
CVE-ID: CVE-2024-44258
CWE-ID: CWE-61
Exploitation vector: Remote access
Vulnerable software:
Apple iOS
iPadOS
Apple iOS
iPadOS
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a symlink following issue in Managed Configuration. A remote attacker can trick the victim into using a malicious backup file, modify protected system files and compromise the affected system.
Remediation
Install updates from vendor's website.