CVE-2016-1755
Apple Mac OSX Kernel - AppleKeyStore Use-After-Free
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.
El kernel en Apple iOS en versiones anteriores a 9.3, OS X en versiones anteriores a 10.11.4, tvOS en versiones anteriores a 9.2 y watchOS en versiones anteriores a 2.2 permite a atacantes ejecutar código arbitrario en un contexto privilegiado o causar una denegación de servicio (corrupción de memoria) a través de una app manipulada, una vulnerabilidad diferente a CVE-2016-1754.
The AppleKeyStore userclient uses an IOCommandGate to serialize access to its userclient methods, however by racing two threads, one of which closes the userclient (which frees the IOCommandGate) and one of which tries to make an external method call we can cause a use-after-free of the IOCommandGate.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-01-13 CVE Reserved
- 2016-03-22 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-01-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1035353 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/39614 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html | 2019-03-25 | |
http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html | 2019-03-25 | |
http://lists.apple.com/archives/security-announce/2016/Mar/msg00002.html | 2019-03-25 | |
http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html | 2019-03-25 | |
https://support.apple.com/HT206166 | 2019-03-25 | |
https://support.apple.com/HT206167 | 2019-03-25 | |
https://support.apple.com/HT206168 | 2019-03-25 | |
https://support.apple.com/HT206169 | 2019-03-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | < 9.3 Search vendor "Apple" for product "Iphone Os" and version " < 9.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | < 10.11.4 Search vendor "Apple" for product "Mac Os X" and version " < 10.11.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Tvos Search vendor "Apple" for product "Tvos" | < 9.2 Search vendor "Apple" for product "Tvos" and version " < 9.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Watchos Search vendor "Apple" for product "Watchos" | < 2.2 Search vendor "Apple" for product "Watchos" and version " < 2.2" | - |
Affected
|