cbcvebase.
CVE-2019-8745
published 2019-12-18

CVE-2019-8745: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15, tvOS 13, iTunes for Windows 12.10.1, iCloud for…

PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.22%
80.7th percentile
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15, tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing a maliciously crafted text file may lead to arbitrary code execution.

Affected

18 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.147.14
appleicloud>= 10.0 < 10.710.7
appleicloud_for_windows
appleicloud_for_windows
appleicloud_for_windows>= unspecified < iCloud for Windows 10.7iCloud for Windows 10.7
appleicloud_for_windows>= unspecified < iCloud for Windows 7.14iCloud for Windows 7.14
appleios
appleitunes< 12.10.112.10.1
appleitunes_12.10.1_for_windows
appleitunes_for_windows>= unspecified < iTunes for Windows 12.10.1iTunes for Windows 12.10.1
applemac_os_x< 10.1510.15
applemacos>= unspecified < macOS Catalina 10.15macOS Catalina 10.15
applemacos_catalina
applemacos_catalina_10.15.1_security_update_2019-001_and_security_update_2019-006
appletvos< 1313
appletvos
appletvos>= unspecified < tvOS 13tvOS 13
applewatchos_6

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.