CVE-2019-8635
published 2019-12-18CVE-2019-8635: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.3th percentile
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.14.5 | 10.14.5 |
| apple | macos | >= unspecified < macOS Mojave 10.14.5 | macOS Mojave 10.14.5 |
| apple | macos_mojave_10.14.5_security_update_2019-003_high_sierra_security_update_2019-0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2019-8635: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
vendor_apple·2019-05-13·CVSS 7.8
CVE-2019-8635 [HIGH] CVE-2019-8635: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
Product: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
CVE: CVE-2019-8635
Component: AMD
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
GHSA
GHSA-mj55-6p4q-86f4: A memory corruption issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2019-8635 [HIGH] CWE-415 GHSA-mj55-6p4q-86f4: A memory corruption issue was addressed with improved memory handling
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
No detection rules found.
No public exploits indexed.
Trendmicro
CVE-2019-8635: Apple macOS Double Free Vulnerability
blogs_trendmicro·2019-06-21·CVSS 7.8
CVE-2019-8635 [HIGH] CVE-2019-8635: Apple macOS Double Free Vulnerability
Exploits & Vulnerabilities
## CVE-2019-8635: Apple macOS Double Free Vulnerability
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component.
By: Moony Li, Lilang Wu Jun 21, 2019 Read time: ( words)
Save to Folio
We discovered a double free vulnerability (assigned as CVE-2019-8635 ) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component. If successfully exploited, an attacker can implement privilege escalation and execute malicious code on the system with root privileges. We disclosed our findings to Apple, which has since released a patch .
The CVE ID covers two flaws, namely in the discard_StretchTex2Tex method and processing of sideband tokens in an AM
Trendmicro
CVE-2019-8635: Apple macOS Double Free Vulnerability
blogs_trendmicro·2019-06-21·CVSS 7.8
CVE-2019-8635 [HIGH] CVE-2019-8635: Apple macOS Double Free Vulnerability
Exploits & Vulnerabilities
# CVE-2019-8635: Apple macOS Double Free Vulnerability
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component.
By: Moony Li, Lilang Wu
2019/06/21
Read time: ( words)
Save to Folio
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component. If successfully exploited, an attacker can implement privilege escalation and execute malicious code on the system with root privileges. We disclosed our findings to Apple, which has since released a patch.
The CVE ID covers two flaws, namely in the discard_StretchTex2Tex method and processing of sideband tokens in an AMD Ra
Trendmicro
CVE-2019-8635: Apple macOS Double Free Vulnerability
blogs_trendmicro·2019-06-21·CVSS 7.8
CVE-2019-8635 [HIGH] CVE-2019-8635: Apple macOS Double Free Vulnerability
Ausnutzung von Schwachstellen
## CVE-2019-8635: Apple macOS Double Free Vulnerability
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component.
By: Moony Li, Lilang Wu Jun 21, 2019 Read time: ( words)
Save to Folio
We discovered a double free vulnerability (assigned as CVE-2019-8635 ) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component. If successfully exploited, an attacker can implement privilege escalation and execute malicious code on the system with root privileges. We disclosed our findings to Apple, which has since released a patch .
The CVE ID covers two flaws, namely in the discard_StretchTex2Tex method and processing of sideband tokens in an
Trendmicro
CVE-2019-8635: Apple macOS Double Free Vulnerability
blogs_trendmicro·2019-06-21·CVSS 7.8
CVE-2019-8635 [HIGH] CVE-2019-8635: Apple macOS Double Free Vulnerability
Exploits & Vulnerabilities
## CVE-2019-8635: Apple macOS Double Free Vulnerability
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component.
By: Moony Li, Lilang Wu 2019/06/21 Read time: ( words)
Save to Folio
We discovered a double free vulnerability (assigned as CVE-2019-8635 ) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component. If successfully exploited, an attacker can implement privilege escalation and execute malicious code on the system with root privileges. We disclosed our findings to Apple, which has since released a patch .
The CVE ID covers two flaws, namely in the discard_StretchTex2Tex method and processing of sideband tokens in an AMD
Trendmicro
CVE-2019-8635: Apple macOS Double Free Vulnerability
blogs_trendmicro·2019-06-21·CVSS 7.8
CVE-2019-8635 [HIGH] CVE-2019-8635: Apple macOS Double Free Vulnerability
Exploits & Vulnerabilities
# CVE-2019-8635: Apple macOS Double Free Vulnerability
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component.
By: Moony Li, Lilang Wu
Jun 21, 2019
Read time: ( words)
Save to Folio
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component. If successfully exploited, an attacker can implement privilege escalation and execute malicious code on the system with root privileges. We disclosed our findings to Apple, which has since released a patch.
The CVE ID covers two flaws, namely in the discard_StretchTex2Tex method and processing of sideband tokens in an AMD
Trendmicro
CVE-2019-8635: Apple macOS Double Free Vulnerability
blogs_trendmicro·2019-06-21·CVSS 7.8
CVE-2019-8635 [HIGH] CVE-2019-8635: Apple macOS Double Free Vulnerability
Exploits y vulnerabilidades
## CVE-2019-8635: Apple macOS Double Free Vulnerability
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component.
By: Moony Li, Lilang Wu Jun 21, 2019 Read time: ( words)
Save to Folio
We discovered a double free vulnerability (assigned as CVE-2019-8635 ) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component. If successfully exploited, an attacker can implement privilege escalation and execute malicious code on the system with root privileges. We disclosed our findings to Apple, which has since released a patch .
The CVE ID covers two flaws, namely in the discard_StretchTex2Tex method and processing of sideband tokens in an A
Trendmicro
CVE-2019-8635: Apple macOS Double Free Vulnerability
blogs_trendmicro·2019-06-21·CVSS 7.8
CVE-2019-8635 [HIGH] CVE-2019-8635: Apple macOS Double Free Vulnerability
Sfruttamento vulnerabilità
## CVE-2019-8635: Apple macOS Double Free Vulnerability
We discovered a double free vulnerability (assigned as CVE-2019-8635) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component.
By: Moony Li, Lilang Wu Jun 21, 2019 Read time: ( words)
Save to Folio
We discovered a double free vulnerability (assigned as CVE-2019-8635 ) in macOS. The vulnerability is caused by a memory corruption flaw in the AMD component. If successfully exploited, an attacker can implement privilege escalation and execute malicious code on the system with root privileges. We disclosed our findings to Apple, which has since released a patch .
The CVE ID covers two flaws, namely in the discard_StretchTex2Tex method and processing of sideband tokens in an AM
2019-12-18
Published