Buffer overflow in macOS - CVE-2021-30937
Published: December 14, 2021 / Updated: September 26, 2022
Vulnerability identifier: #VU58862
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30937
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in the OS kernel subsystem. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code with kernel privileges.
Affected software
macOS
watchOS
tvOS
Apple iOS
iPadOS
watchOS
tvOS
Apple iOS
iPadOS
How to mitigate CVE-2021-30937
Install updates from vendor's website.
macOS - addressed in versions 12.1 21C52, 10.15.7 19H1615, 11.6.2 20G314
watchOS - update to 8.3 19S55
tvOS - update to 15.2 19K53
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57
iPadOS - update to 15.2 19C56
watchOS - update to 8.3 19S55
tvOS - update to 15.2 19K53
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57
iPadOS - update to 15.2 19C56