Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-2361Cross-site Scripting in Apple MAC OS X

Severity
6.1MEDIUMNVD
EPSS
6.2%
top 9.14%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedFeb 20
Latest updateMay 17

Description

An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDapple/mac_os_x10.12.2
Appleapple/macos_sierra10.12.3

🔴Vulnerability Details

1
GHSA
GHSA-xjfg-8p96-4jw7: An issue was discovered in certain Apple products2022-05-17

💥Exploits & PoCs

1
Exploit-DB
Apple macOS HelpViewer 10.12.1 - XSS Leads to Arbitrary File Execution / Arbitrary File Read2017-02-23

🔍Detection Rules

1
Suricata
ET WEB_CLIENT Possible MacOSX HelpViewer 10.12.1 XSS Arbitrary File Execution and Arbitrary File Read (CVE-2017-2361)2017-03-08

📋Vendor Advisories

1
Apple
CVE-2017-2361: macOS Sierra 10.12.32017-01-23