CVE-2014-4461
published 2014-11-18CVE-2014-4461: The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.40%
87.6th percentile
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 8.1 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | mac_os_x | <= 10.10.1 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | os_x_yosemite_v10.10.2_and_security_update_2015-001 | — | — |
| apple | tvos | <= 7.0.1 | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r7m3-66qf-cgxx: The kernel in Apple iOS before 8
ghsa_unreviewed·2022-05-14
CVE-2014-4461 [HIGH] CWE-20 GHSA-r7m3-66qf-cgxx: The kernel in Apple iOS before 8
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
Project0
Deja-XNU - Project Zero
project_zero·2018-10-01·CVSS 7.8
CVE-2014-4388 [HIGH] Deja-XNU - Project Zero
Posted by Ian Beer, Google Project Zero
This blog post revisits an old bug found by Pangu Team and combines it with a new, albeit very similar issue I recently found to try to build a "perfect" exploit for iOS 7.1.2.
State of the art
An idea I've wanted to play with for a while is to revisit old bugs and try to exploit them again, but using what I've learnt in the meantime about iOS. My hope is that it would give an insight into what the state-of-the-art of iOS exploitation could have looked like a few years ago, and might prove helpful if extrapolated forwards to think about what state-of-the-art exploitation might look like now.
So let's turn back the clock to 2014...
Pangu 7
On June 23 2014 @PanguTeam released the Pangu 7 jailbreak for iOS 7.1-7.1.x. They exploited a lot of bu
Apple
CVE-2014-4461: OS X Yosemite v10.10.2 and Security Update 2015-001
vendor_apple·CVSS 9.3
CVE-2014-4461 [CRITICAL] CVE-2014-4461: OS X Yosemite v10.10.2 and Security Update 2015-001
Apple Security Update: About the security content of OS X Yosemite v10.10.2 and Security Update 2015-001
Product: OS X Yosemite v10.10.2 and Security Update 2015-001
CVE: CVE-2014-4461
Component: CVE-ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2014/Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2014/Nov/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00003.htmlhttp://support.apple.com/HT204244http://www.securityfocus.com/bid/71136http://www.securitytracker.com/id/1031231https://exchange.xforce.ibmcloud.com/vulnerabilities/98774https://support.apple.com/en-us/HT204418https://support.apple.com/en-us/HT204420https://support.apple.com/en-us/HT6590https://support.apple.com/en-us/HT6592http://lists.apple.com/archives/security-announce/2014/Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2014/Nov/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00003.htmlhttp://support.apple.com/HT204244http://www.securityfocus.com/bid/71136http://www.securitytracker.com/id/1031231https://exchange.xforce.ibmcloud.com/vulnerabilities/98774https://support.apple.com/en-us/HT204418https://support.apple.com/en-us/HT204420https://support.apple.com/en-us/HT6590https://support.apple.com/en-us/HT6592
2014-11-18
Published