cbcvebase.
CVE-2017-7172
published 2018-04-03

CVE-2017-7172: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected…

high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CFNetwork Session" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

Affected

12 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.27.2
appleicloud_for_windows
appleios
appleiphone_os< 11.211.2
appleitunes< 12.7.212.7.2
appleitunes_12.7.2_for_windows
applemac_os_x< 10.13.210.13.2
applemacos_high_sierra_10.13.2_security_update_2017-002_sierra_and_security_update_20
appletvos< 11.211.2
appletvos
applewatchos< 4.24.2
applewatchos