CVE-2019-8801
published 2019-12-18CVE-2019-8801: A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.39%
31.1th percentile
A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | < 12.10.2 | 12.10.2 |
| apple | itunes_12.10.2_for_windows | — | — |
| apple | itunes_for_windows | >= unspecified < iTunes for Windows 12.10.2 | iTunes for Windows 12.10.2 |
| apple | mac_os_x | < 10.15.1 | 10.15.1 |
| apple | macos | >= unspecified < macOS Catalina 10.15.1 | macOS Catalina 10.15.1 |
| apple | macos_catalina_10.15.1_security_update_2019-001_and_security_update_2019-006 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2019-8801: iTunes 12.10.2 for Windows
vendor_apple·2019-10-30·CVSS 7.8
CVE-2019-8801 [HIGH] CVE-2019-8801: iTunes 12.10.2 for Windows
Apple Security Update: About the security content of iTunes 12.10.2 for Windows
Product: iTunes 12.10.2 for Windows
CVE: CVE-2019-8801
Component: Graphics Driver
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2019-8801: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006
vendor_apple·2019-10-29·CVSS 7.8
CVE-2019-8801 [HIGH] CVE-2019-8801: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006
Apple Security Update: About the security content of macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006
Product: macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006
CVE: CVE-2019-8801
Component: IOGraphics
Impact: A local user may be able to cause unexpected system termination or read kernel memory
Description: An out-of-bounds read was addressed with improved bounds checking.
GHSA
GHSA-c9xp-93v6-v7gj: A dynamic library loading issue existed in iTunes setup
ghsa_unreviewed·2022-05-24
CVE-2019-8801 [MEDIUM] GHSA-c9xp-93v6-v7gj: A dynamic library loading issue existed in iTunes setup
A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-18
Published