Integer overflow in macOS - CVE-2020-9841

 

Integer overflow in macOS - CVE-2020-9841

Published: May 28, 2020


Vulnerability identifier: #VU28310
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9841
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the SkyLight module. A local user can pass specially crafted data to the application, trigger integer overflow, escalate privileges and execute arbitrary code in the context of WindowServer.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

macOS

How to mitigate CVE-2020-9841

Install updates from vendor's website.

macOS - update to 10.15.5 19F96

External References

Related Security Bulletins