cbcvebase.
CVE-2019-8848
published 2020-10-27

CVE-2019-8848: This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security…

PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.00%
58.9th percentile
This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An application may be able to gain elevated privileges.

Affected

23 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.167.16
appleicloud>= 10.0 < 10.910.9
appleicloud_for_windows
appleicloud_for_windows
appleios_13.3_and_ipados
appleios_and_ipados>= unspecified < 13.313.3
appleipados< 13.313.3
appleiphone_os< 13.313.3
appleitunes< 12.10.312.10.3
appleitunes_12.10.3_for_windows
applemac_os_x< 10.15.210.15.2
applemacos>= unspecified < 10.1510.15
applemacos>= unspecified < 6.16.1
applemacos>= unspecified < 13.313.3
applemacos>= unspecified < 12.1012.10
applemacos>= unspecified < 10.910.9
applemacos>= unspecified < 7.167.16
applemacos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007
applesafari< 13.0.313.0.3
appletvos< 13.313.3
appletvos
applewatchos< 6.1.16.1.1
applewatchos

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.