Information disclosure in macOS - CVE-2018-4223
Published: June 4, 2018
Vulnerability identifier: #VU13169
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4223
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to a state management error in the Security component. A local attacker can read a persistent account identifier.
Affected software
macOS
watchOS
tvOS
Apple iOS
IBM Watson Explorer Deep Analytics Edition Analytical Components
watchOS
tvOS
Apple iOS
IBM Watson Explorer Deep Analytics Edition Analytical Components
How to mitigate CVE-2018-4223
Update to version 10.13.4.
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.16