CVE-2016-1803
Apple OS X IOKit CoreCaptureResponder Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
CoeCapture en Apple iOS en versiones anteriores a 9.3.2, OS X en versiones anteriores a 10.11.5, tvOS en versiones anteriores a 9.2.1 y watchOS en versiones anteriores a 2.2.1 permite a atacantes ejecutar código arbitrario en un contexto privilegiado o causar una denegación de servicio (referencia a puntero NULL) a través de una app manipulada.
This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Apple OS X. User interaction is required to exploit this vulnerability in that the target must open a malicious file.
The specific flaw exists within CoreCaptureResponder in IOKit. The issue lies with the failure to validate user-supplied arguments which can cause a null pointer dereference. An attacker can leverage this vulnerability to escalate privileges and execute code under the context of the kernel.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-01-13 CVE Reserved
- 2016-05-17 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/137399/OS-X-CoreCaptureResponder-NULL-Pointer-Dereference.html | Third Party Advisory | |
http://www.securityfocus.com/bid/90694 | Third Party Advisory | |
http://www.securitytracker.com/id/1035890 | Third Party Advisory | |
http://www.zerodayinitiative.com/advisories/ZDI-16-339 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/39925 | 2024-08-05 | |
https://bugs.chromium.org/p/project-zero/issues/detail?id=777 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2016/May/msg00001.html | 2019-03-25 | |
http://lists.apple.com/archives/security-announce/2016/May/msg00002.html | 2019-03-25 | |
http://lists.apple.com/archives/security-announce/2016/May/msg00003.html | 2019-03-25 | |
http://lists.apple.com/archives/security-announce/2016/May/msg00004.html | 2019-03-25 | |
https://support.apple.com/HT206564 | 2019-03-25 | |
https://support.apple.com/HT206566 | 2019-03-25 | |
https://support.apple.com/HT206567 | 2019-03-25 | |
https://support.apple.com/HT206568 | 2019-03-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Watchos Search vendor "Apple" for product "Watchos" | < 2.2.1 Search vendor "Apple" for product "Watchos" and version " < 2.2.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | < 9.3.2 Search vendor "Apple" for product "Iphone Os" and version " < 9.3.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | < 10.11.5 Search vendor "Apple" for product "Mac Os X" and version " < 10.11.5" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Tvos Search vendor "Apple" for product "Tvos" | < 9.2.1 Search vendor "Apple" for product "Tvos" and version " < 9.2.1" | - |
Affected
|