CVE-2015-1133Improper Input Validation in Apple MAC OS X

Severity
10.0CRITICALNVD
NVD7.2
EPSS
0.1%
top 77.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 14

Description

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1134, and CVE-2015-1135.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

5
GHSA
GHSA-8chp-c6p4-xcv5: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14
GHSA
GHSA-vgj7-5chx-3pc8: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14
GHSA
GHSA-qrcw-fxf5-mcw6: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14
GHSA
GHSA-ghcq-pgwv-hvxp: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14
GHSA
GHSA-6x5j-jg26-j3c8: fontd in Apple Type Services (ATS) in Apple OS X before 102022-05-14

💥Exploits & PoCs

1
Exploit-DB
Trend Micro 8.0.1133 (Multiple Products) - Local Privilege Escalation2015-01-31

📋Vendor Advisories

1
Apple
CVE-2015-1133: OS X Yosemite v10.10.3 and Security Update 2015-004