cbcvebase.
CVE-2020-9859
published 2020-06-05

CVE-2020-9859: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5…

PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
0.83%
53.4th percentile
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.

Affected

9 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.5.1 and iPadOS 13.5.1iOS 13.5.1 and iPadOS 13.5.1
appleipados< 13.5.113.5.1
appleiphone_os< 13.5.113.5.1
applemac_os_x< 10.15.510.15.5
applemacos>= unspecified < macOS Catalina 10.15.5 Supplemental UpdatemacOS Catalina 10.15.5 Supplemental Update
appletvos< 13.4.613.4.6
appletvos>= unspecified < tvOS 13.4.6tvOS 13.4.6
applewatchos< 6.2.66.2.6
applewatchos>= unspecified < watchOS 6.2.6watchOS 6.2.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.