CVE-2020-27911
published 2020-12-08CVE-2020-27911: An integer overflow was addressed through improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud…
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.21%
86.7th percentile
An integer overflow was addressed through improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 11.5 | 11.5 |
| apple | ios_14.2_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 14.2 | 14.2 |
| apple | ipados | < 14.2 | 14.2 |
| apple | iphone_os | < 14.2 | 14.2 |
| apple | itunes | < 12.11 | 12.11 |
| apple | macos | >= 11.0 < 11.0.1 | 11.0.1 |
| apple | macos | >= unspecified < 11.0 | 11.0 |
| apple | macos | >= unspecified < 12.11 | 12.11 |
| apple | macos | >= unspecified < 11.5 | 11.5 |
| apple | tvos | < 14.2 | 14.2 |
| apple | tvos | >= unspecified < 14.2 | 14.2 |
| apple | watchos | < 7.1 | 7.1 |
| apple | watchos | >= unspecified < 7.1 | 7.1 |
| msrc | 3d_viewer | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_visio_2016 | — | — |
| msrc | microsoft_visual_studio_2013_update_5 | — | — |
| msrc | microsoft_visual_studio_2015_update_3 | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior
vendor_msrc·2023-06-13·CVSS 7.8
CVE-2023-27911 [HIGH] CWE-122 AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior
AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior
FAQ: Why is this AutoDesk CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in AutoDesk software which is consumed by the Microsoft products listed in the Security Updates table. It is being documented in the Security Update Guide to announce that the latest builds of these products are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
Visual Studio: Visual Studio
AutoDesk: AutoDesk
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https:
Apple
CVE-2020-27911: iOS 14.2 and iPadOS 14.2
vendor_apple·2020-11-05·CVSS 7.8
CVE-2020-27911 [HIGH] CVE-2020-27911: iOS 14.2 and iPadOS 14.2
Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2
Product: iOS 14.2 and iPadOS
Version: 14.2
CVE: CVE-2020-27911
Component: Keyboard
Impact: A person with physical access to an iOS device may be able to access stored passwords without authentication
Description: An authentication issue was addressed with improved state management.
GHSA
GHSA-hf7r-8668-4mm7: An integer overflow was addressed through improved input validation
ghsa_unreviewed·2022-05-24
CVE-2020-27911 [HIGH] CWE-190 GHSA-hf7r-8668-4mm7: An integer overflow was addressed through improved input validation
An integer overflow was addressed through improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2020/Dec/26http://seclists.org/fulldisclosure/2020/Dec/32https://support.apple.com/en-us/HT211928https://support.apple.com/en-us/HT211929https://support.apple.com/en-us/HT211930https://support.apple.com/en-us/HT211931https://support.apple.com/en-us/HT211933https://support.apple.com/en-us/HT211935https://support.apple.com/kb/HT212011http://seclists.org/fulldisclosure/2020/Dec/26http://seclists.org/fulldisclosure/2020/Dec/32https://support.apple.com/en-us/HT211928https://support.apple.com/en-us/HT211929https://support.apple.com/en-us/HT211930https://support.apple.com/en-us/HT211931https://support.apple.com/en-us/HT211933https://support.apple.com/en-us/HT211935https://support.apple.com/kb/HT212011
2020-12-08
Published