CVE-2019-8509Apple Macos vulnerability

7 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.3%
top 50.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateMay 24

Description

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. A malicious application may be able to elevate privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5apple/macosunspecified10.15
NVDapple/mac_os_x10.13.610.15.1

🔴Vulnerability Details

2
GHSA
GHSA-676w-c8rg-vhg2: This issue was addressed by removing the vulnerable code2022-05-24
CVEList
CVE-2019-8509: This issue was addressed by removing the vulnerable code2020-10-27

📋Vendor Advisories

2
Apple
CVE-2019-8509: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-0062019-10-29
Apple
CVE-2019-8509: macOS Catalina 10.152019-10-07

🕵️Threat Intelligence

2
Sentinelone
Privilege Escalation | macOS Malware & The Path to Root Part 1 - SentinelLabs2019-11-06
Sentinelone
Privilege Escalation | macOS Malware & The Path to Root Part 12019-11-06
CVE-2019-8509 — Apple Macos vulnerability | cvebase