Memory corruption in macOS - CVE-2018-4407
Published: October 31, 2018 / Updated: April 27, 2020
Vulnerability identifier: #VU15607
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4407
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote authenticated attacker to execute arbitrary code on the target system.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
macOS
How to mitigate CVE-2018-4407
Update to version 10.14.1.
macOS - update to 10.14.1 18B75
Links to Public Exploits and PoC-codes
- Exploit #2607 - iOS-Kernel-Crash (Exploit for CVE-2018-4407-Memory Corruption) (April 27, 2020)
- Exploit #2295 - Exploits (Containing Self Made Perl Reproducers / PoC Codes) (April 7, 2020)
- Exploit #1968 - CVE-2018-4407-iOS-exploit (CVE-2018-4407,iOS exploit) (March 18, 2020)
- Exploit #2059 - iOS-Kernel-Crash (Exploit for CVE-2018-4407-Memory Corruption) (March 18, 2020)
- Exploit #2099 - AppleDOS (Messing Apple devices on the network with CVE-2018-4407 (heap overflow in bad packet handling)) (March 18, 2020)
- Exploit #216 - labs (Vulnerability Labs for security analysis) (March 18, 2020)
- Exploit #217 - node-cve-2018-4407 (Node.js PoC exploit code for CVE-2018-4407) (March 18, 2020)
- Exploit #218 - CVE-2018-4407 (IOS/MAC Denial-Of-Service [POC/EXPLOIT FOR MASSIVE ATTACK TO IOS/MAC IN NETWORK]) (March 18, 2020)
- Exploit #219 - wifi (iOS 11 WiFi Exploit - icmp_error_CVE-2018-4407) (March 18, 2020)
- Exploit #220 - CVE-2018-4407-IOS (POC: Heap buffer overflow in the networking code in the XNU operating system kernel) (March 18, 2020)