#VU17144 Privilege escalation in Apple iOS - CVE-2019-6210
Published: January 23, 2019 / Updated: January 29, 2019
Vulnerability identifier: #VU17144
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-6210
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Apple iOS
Apple iOS
Software vendor:
Apple Inc.
Apple Inc.
Description
The vulnerability allows a local authenticated attacker to gain elevated privileges.
The weakness exists due to an error in the Kernel component when handling malicious input. A local authenticated attacker can run a specially crafted application and execute arbitrary code with kernel privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to an error in the Kernel component when handling malicious input. A local authenticated attacker can run a specially crafted application and execute arbitrary code with kernel privileges.
Successful exploitation of the vulnerability may result in system compromise.
Remediation
Update to version 12.1.3.