CVE-2016-4617
published 2017-02-20CVE-2016-4617: An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process spawning in…
PriorityP337high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.30%
21.8th percentile
An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process spawning in the "libxpc" component.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.6 | — |
| apple | macos_sierra | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-4617: macOS Sierra 10.12
vendor_apple·2016-09-20·CVSS 8.8
CVE-2016-4617 [HIGH] CVE-2016-4617: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-4617
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: Multiple memory corruption issues were addressed through improved memory handling.
GHSA
GHSA-qp5g-r5vm-f94v: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-17
CVE-2016-4617 [HIGH] GHSA-qp5g-r5vm-f94v: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process spawning in the "libxpc" component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-20
Published