CVE-2016-1742Apple Itunes vulnerability

CWE-2644 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.2%
top 62.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Latest updateMay 17

Description

Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDapple/itunes12.3.1

🔴Vulnerability Details

2
GHSA
GHSA-qcc8-2v4m-qw7h: Untrusted search path vulnerability in the installer in Apple iTunes before 122022-05-17
CVEList
CVE-2016-1742: Untrusted search path vulnerability in the installer in Apple iTunes before 122016-05-20

📋Vendor Advisories

1
Apple
CVE-2016-1742: iTunes 12.4
CVE-2016-1742 — Apple Itunes vulnerability | cvebase