Privilege escalation in Apple iOS - CVE-2019-6210

 

Privilege escalation in Apple iOS - CVE-2019-6210

Published: January 23, 2019 / Updated: January 29, 2019


Vulnerability identifier: #VU17144
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6210
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated attacker to gain elevated privileges.

The weakness exists due to an error in the Kernel component when handling malicious input. A local authenticated attacker can run a specially crafted application and execute arbitrary code with kernel privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Apple iOS
watchOS
macOS
tvOS

How to mitigate CVE-2019-6210

Update to version 12.1.3.

Apple iOS - update to 12.1.3 16D39
watchOS - update to 5.1.3
macOS - update to 10.14.3 18D42
tvOS - update to 12.1.2

External References

Related Security Bulletins