CVE-2019-6232
published 2019-12-18CVE-2019-6232: A race condition existed during the installation of iTunes for Windows. This was addressed with improved state handling. This issue is fixed in iCloud for…
PriorityP337high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
1.17%
64.2th percentile
A race condition existed during the installation of iTunes for Windows. This was addressed with improved state handling. This issue is fixed in iCloud for Windows 7.11. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.11 | 7.11 |
| apple | icloud_for_windows | — | — |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 7.11 | iCloud for Windows 7.11 |
| kde | kconfig | >= 0 < 5.18.0-0ubuntu1.1 | 5.18.0-0ubuntu1.1 |
| kde | kconfig | >= 0 < 5.44.0-0ubuntu1.1 | 5.44.0-0ubuntu1.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2019-6232: iCloud for Windows 7.11
vendor_apple·2019-03-25·CVSS 7.5
CVE-2019-6232 [HIGH] CVE-2019-6232: iCloud for Windows 7.11
Apple Security Update: About the security content of iCloud for Windows 7.11
Product: iCloud for Windows
Version: 7.11
CVE: CVE-2019-6232
Component: CoreCrypto
Impact: A malicious application may be able to elevate privileges
Description: A buffer overflow was addressed with improved bounds checking.
GHSA
GHSA-mgvm-678f-6rwc: A race condition existed during the installation of iTunes for Windows
ghsa_unreviewed·2022-05-24
CVE-2019-6232 [HIGH] GHSA-mgvm-678f-6rwc: A race condition existed during the installation of iTunes for Windows
A race condition existed during the installation of iTunes for Windows. This was addressed with improved state handling. This issue is fixed in iCloud for Windows 7.11. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
OSV
kconfig, kde4libs vulnerabilities
osv·2019-08-16·CVSS 7.5
CVE-2019-14744 kconfig, kde4libs vulnerabilities
kconfig, kde4libs vulnerabilities
It was discovered that KConfig and KDE libraries have a vulnerability
where an attacker could hide malicious code under desktop and
configuration files. (CVE-2019-14744)
It was discovered that KConfig allows remote attackers to write to
arbitrary files via a ../ in a filename in an archive file. (CVE-2016-6232)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-18
Published