CVE-2017-13864
Apple Security Advisory 2017-12-13-4
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue involves the "APNs Server" component. It allows man-in-the-middle attackers to track users by leveraging mishandling of client certificates.
Se ha descubierto un problema en ciertos productos Apple. Se han visto afectadas las versiones de iCloud anteriores a la 7.2 en Windows y las versiones de iTunes anteriores a la 12.7.2 en Windows. El problema afecta al componente "APNs Server". Permite que atacantes de Man-in-the-Middle (MitM) rastreen usuarios aprovechando la gestión incorrecta de certificados de cliente.
iTunes 12.7.2 for Windows is now available and addresses code execution and privacy issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-30 CVE Reserved
- 2017-12-16 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102192 | Third Party Advisory | |
http://www.securitytracker.com/id/1040013 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.apple.com/HT208326 | 2017-12-28 | |
https://support.apple.com/HT208328 | 2017-12-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Icloud Search vendor "Apple" for product "Icloud" | < 7.2 Search vendor "Apple" for product "Icloud" and version " < 7.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Apple Search vendor "Apple" | Itunes Search vendor "Apple" for product "Itunes" | < 12.7.2 Search vendor "Apple" for product "Itunes" and version " < 12.7.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|