Buffer overflow in macOS - CVE-2021-30949
Published: December 14, 2021
Vulnerability identifier: #VU58865
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30949
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in the OS kernel subsystem. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code with kernel privileges.
Affected software
macOS
watchOS
tvOS
Apple iOS
iPadOS
watchOS
tvOS
Apple iOS
iPadOS
How to mitigate CVE-2021-30949
Install updates from vendor's website.
macOS - addressed in versions 12.1 21C52, 10.15.7 19H1615, 11.6.2 20G314
watchOS - update to 8.3 19S55
tvOS - update to 15.2 19K53
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57
iPadOS - update to 15.2 19C56
watchOS - update to 8.3 19S55
tvOS - update to 15.2 19K53
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57
iPadOS - update to 15.2 19C56