CVE-2018-4206
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Crash Reporter" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app that replaces a privileged port name.
Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3.1, las versiones de macOS anteriores a la 10.13.4 Security Update 2018-001, las versiones de tvOS anteriores a la 11.4 y las versiones de watchOS anteriores a la 4.3.1 se han visto afectadas. El problema implica el componente "Crash Reporter". Permite que los atacantes ejecuten código arbitrario o provoquen una denegación de servicio (corrupción de memoria) mediante una app manipulada que reemplaza un nombre de puerto privilegiado.
macOS/iOS ReportCrash suffers from a mach port replacement due to failure to respect MIG ownership rules.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-02 CVE Reserved
- 2018-04-26 CVE Published
- 2023-10-30 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103957 | Third Party Advisory | |
http://www.securityfocus.com/bid/103958 | Third Party Advisory | |
http://www.securitytracker.com/id/1040744 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/44562 | 2024-08-05 | |
https://bugs.chromium.org/p/project-zero/issues/detail?id=1529 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.apple.com/HT208742 | 2018-07-17 | |
https://support.apple.com/HT208743 | 2018-07-17 | |
https://support.apple.com/HT208850 | 2018-07-17 | |
https://support.apple.com/HT208851 | 2018-07-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Apple Tv Search vendor "Apple" for product "Apple Tv" | < 11.4 Search vendor "Apple" for product "Apple Tv" and version " < 11.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | < 11.3.1 Search vendor "Apple" for product "Iphone Os" and version " < 11.3.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | < 10.13.4 Search vendor "Apple" for product "Mac Os X" and version " < 10.13.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Watchos Search vendor "Apple" for product "Watchos" | < 4.3.1 Search vendor "Apple" for product "Watchos" and version " < 4.3.1" | - |
Affected
|