CVE-2020-9818
published 2020-06-09CVE-2020-9818: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5…
PriorityP180high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
2.29%
81.2th percentile
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < iOS 13.5 and iPadOS 13.5 | iOS 13.5 and iPadOS 13.5 |
| apple | ios-1 | >= unspecified < iOS 12.4.7 | iOS 12.4.7 |
| apple | ipados | < 13.5 | 13.5 |
| apple | iphone_os | < 12.4.7 | 12.4.7 |
| apple | iphone_os | >= 13.0 < 13.5 | 13.5 |
| apple | watchos | < 6.2.5 | 6.2.5 |
| apple | watchos | >= unspecified < watchOS 6.2.5 | watchOS 6.2.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2020-9818 is an out-of-bounds write flaw originating from the MFMutableData interface in the MIME framework in iOS; the flaw exists because MFMutableData does not handle errors from the ftruncate() system call ↗
- →On iOS 13, the heap overflow (CVE-2020-9819) can be triggered zero-click via a specially crafted email; on iOS 12, user interaction (clicking the email) is required unless the attacker controls the mail server ↗
- →CVE-2020-9818 (out-of-bounds write) requires an additional vulnerability allowing an arbitrary selector call to trigger remotely; monitor for chained exploit activity involving the iOS Mail app ↗
- →Exploitation is delivered via a specially crafted email to the victim; detection should focus on anomalous or oversized email messages processed by the iOS Mail app ↗
- →ZecOps (who named the exploit chain 'MailDemon') observed in-the-wild exploitation as early as January 2018 against iOS 11.2.2; threat hunting should consider historical mail logs from that period onward ↗
- →Successful exploitation grants attacker capability to leak, modify, or delete emails within the Mail app context; monitor for unexpected Mail app data access or modification ↗
- →Known targeted victims include Fortune 500 employees, carrier executives, managed security service providers, and journalists; prioritize investigation for these high-value target profiles ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r647-89qj-xwmp: An out-of-bounds write issue was addressed with improved bounds checking
ghsa_unreviewed·2022-05-24
CVE-2020-9818 [MEDIUM] CWE-787 GHSA-r647-89qj-xwmp: An out-of-bounds write issue was addressed with improved bounds checking
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.
VulnCheck
Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
vulncheck·2020·CVSS 8.8
CVE-2020-9818 [HIGH] CWE-787 Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.
Affected: Apple iOS, iPadOS, and watchOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.tenable.com/blog/multiple-zero-day-vulnerabilities-in-ios-mail-app-exploited-in-the-wild; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-03
CISA
Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2020-9818 [HIGH] CWE-787 Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
Vulnerability: Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
Affected: Apple iOS, iPadOS, and watchOS
Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-9818
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
Qualys
Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR | Qualys
blogs_qualys·2021-02-10·CVSS 7.8
[HIGH] Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR | Qualys
As mobile devices have become ubiquitous in almost every business process, whether in bank branches, manufacturing sites or retail stores, they are now hosting business applications and data that is subject to regulatory compliance and security. With access to critical corporate resources inside the corporate network, these mobile devices have become critical assets for the organization.
### Mobile Attack Surface Challenges
Alongside this trend, there has been a drastic rise in Android, iOS, and iPadOS vulnerabilities and an increased number of vulnerable apps distributed from authorized app stores. Through these vectors, mobile devices have become preferred targets for attackers to gain an entry point into corporate networks. Last year, for example, 900 million Apple iOS users were affe
Qualys
Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR
blogs_qualys·2021-02-10·CVSS 7.8
[HIGH] Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR
As mobile devices have become ubiquitous in almost every business process, whether in bank branches, manufacturing sites or retail stores, they are now hosting business applications and data that is subject to regulatory compliance and security. With access to critical corporate resources inside the corporate network, these mobile devices have become critical assets for the organization.
## Mobile Attack Surface Challenges
Alongside this trend, there has been a drastic rise in Android, iOS, and iPadOS vulnerabilities and an increased number of vulnerable apps distributed from authorized app stores. Through these vectors, mobile devices have become preferred targets for attackers to gain an entry point into corporate networks. Last year, for example, 900 million Apple iOS users were affec
Tenable
CVE-2020-9818, CVE-2020-9819: Multiple Zero-Day Vulnerabilities in iOS Mail App Exploited in the Wild
blogs_tenable·2020-04-22·CVSS 8.8
[HIGH] CVE-2020-9818, CVE-2020-9819: Multiple Zero-Day Vulnerabilities in iOS Mail App Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2020-06-09
Published
2021-11-03
Added to CISA KEV
Exploited in the wild