CVE-2019-8848
published 2020-10-27CVE-2019-8848: This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.00%
58.9th percentile
This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An application may be able to gain elevated privileges.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.16 | 7.16 |
| apple | icloud | >= 10.0 < 10.9 | 10.9 |
| apple | icloud_for_windows | — | — |
| apple | icloud_for_windows | — | — |
| apple | ios_13.3_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 13.3 | 13.3 |
| apple | ipados | < 13.3 | 13.3 |
| apple | iphone_os | < 13.3 | 13.3 |
| apple | itunes | < 12.10.3 | 12.10.3 |
| apple | itunes_12.10.3_for_windows | — | — |
| apple | mac_os_x | < 10.15.2 | 10.15.2 |
| apple | macos | >= unspecified < 10.15 | 10.15 |
| apple | macos | >= unspecified < 6.1 | 6.1 |
| apple | macos | >= unspecified < 13.3 | 13.3 |
| apple | macos | >= unspecified < 12.10 | 12.10 |
| apple | macos | >= unspecified < 10.9 | 10.9 |
| apple | macos | >= unspecified < 7.16 | 7.16 |
| apple | macos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007 | — | — |
| apple | safari | < 13.0.3 | 13.0.3 |
| apple | tvos | < 13.3 | 13.3 |
| apple | tvos | — | — |
| apple | watchos | < 6.1.1 | 6.1.1 |
| apple | watchos | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2019-8848: iCloud for Windows 7.16
vendor_apple·2019-12-11·CVSS 7.8
CVE-2019-8848 [HIGH] CVE-2019-8848: iCloud for Windows 7.16
Apple Security Update: About the security content of iCloud for Windows 7.16
Product: iCloud for Windows
Version: 7.16
CVE: CVE-2019-8848
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-8848: iTunes 12.10.3 for Windows
vendor_apple·2019-12-11·CVSS 7.8
CVE-2019-8848 [HIGH] CVE-2019-8848: iTunes 12.10.3 for Windows
Apple Security Update: About the security content of iTunes 12.10.3 for Windows
Product: iTunes 12.10.3 for Windows
CVE: CVE-2019-8848
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-8848: iCloud for Windows 10.9
vendor_apple·2019-12-11·CVSS 7.8
CVE-2019-8848 [HIGH] CVE-2019-8848: iCloud for Windows 10.9
Apple Security Update: About the security content of iCloud for Windows 10.9
Product: iCloud for Windows
Version: 10.9
CVE: CVE-2019-8848
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-8848: iOS 13.3 and iPadOS 13.3
vendor_apple·2019-12-10·CVSS 7.8
CVE-2019-8848 [HIGH] CVE-2019-8848: iOS 13.3 and iPadOS 13.3
Apple Security Update: About the security content of iOS 13.3 and iPadOS 13.3
Product: iOS 13.3 and iPadOS
Version: 13.3
CVE: CVE-2019-8848
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-8848: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
vendor_apple·2019-12-10·CVSS 7.8
CVE-2019-8848 [HIGH] CVE-2019-8848: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Product: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
CVE: CVE-2019-8848
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-8848: watchOS 6.1.1
vendor_apple·2019-12-10·CVSS 7.8
CVE-2019-8848 [HIGH] CVE-2019-8848: watchOS 6.1.1
Apple Security Update: About the security content of watchOS 6.1.1
Product: watchOS
Version: 6.1.1
CVE: CVE-2019-8848
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2019-8848: tvOS 13.3
vendor_apple·2019-12-10·CVSS 7.8
CVE-2019-8848 [HIGH] CVE-2019-8848: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-8848
Component: CFNetwork Proxies
Impact: An application may be able to gain elevated privileges
Description: This issue was addressed with improved checks.
GHSA
GHSA-33rp-rjjm-5r9m: This issue was addressed with improved checks
ghsa_unreviewed·2022-05-24
CVE-2019-8848 [HIGH] CWE-269 GHSA-33rp-rjjm-5r9m: This issue was addressed with improved checks
This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An application may be able to gain elevated privileges.
No detection rules found.
No public exploits indexed.
Sentinelone
macOS Catalina 10.15.2 Update: What's New
blogs_sentinelone·2019-12-12·CVSS 8.8
[HIGH] macOS Catalina 10.15.2 Update: What's New
It’s been two months since Apple dropped the initial release of macOS Catalina, and after a rapid few supplemental updates and a first point upgrade in the first month, things appear to have slowed down to a normal cadence. This week, Apple dropped the public release of 10.15.2, a full month after showing developers the first beta. So, what’s changed in this update? Let’s take a look and see!
## Features and Tweaks
After installing the 10.15.2 update, users should find they are now on build 19C57. While point updates are not typically opportunities for Apple to add new features, 10.15.2 does bring a small number of user level additions.
Apple News receives a new layout and now carries content from the Wall Street Journal and other “leading newspapers”, while Stocks adds links to related
Sentinelone
macOS Catalina 10.15.2 Update: What's New
blogs_sentinelone·2019-12-12·CVSS 8.8
[HIGH] macOS Catalina 10.15.2 Update: What's New
It’s been two months since Apple dropped the initial release of macOS Catalina, and after a rapid few supplemental updates and a first point upgrade in the first month, things appear to have slowed down to a normal cadence. This week, Apple dropped the public release of 10.15.2, a full month after showing developers the first beta. So, what’s changed in this update? Let’s take a look and see!
## Features and Tweaks
After installing the 10.15.2 update, users should find they are now on build 19C57 . While point updates are not typically opportunities for Apple to add new features, 10.15.2 does bring a small number of user level additions.
Apple News receives a new layout and now carries content from the Wall Street Journal and other “leading newspapers”, while Stocks adds links to relate
https://support.apple.com/en-us/HT210785https://support.apple.com/en-us/HT210788https://support.apple.com/en-us/HT210789https://support.apple.com/en-us/HT210790https://support.apple.com/en-us/HT210793https://support.apple.com/en-us/HT210794https://support.apple.com/en-us/HT210795https://support.apple.com/en-us/HT210785https://support.apple.com/en-us/HT210788https://support.apple.com/en-us/HT210789https://support.apple.com/en-us/HT210790https://support.apple.com/en-us/HT210793https://support.apple.com/en-us/HT210794https://support.apple.com/en-us/HT210795
2020-10-27
Published