CVE-2020-9859
published 2020-06-05CVE-2020-9859: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5…
PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
0.83%
53.4th percentile
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < iOS 13.5.1 and iPadOS 13.5.1 | iOS 13.5.1 and iPadOS 13.5.1 |
| apple | ipados | < 13.5.1 | 13.5.1 |
| apple | iphone_os | < 13.5.1 | 13.5.1 |
| apple | mac_os_x | < 10.15.5 | 10.15.5 |
| apple | macos | >= unspecified < macOS Catalina 10.15.5 Supplemental Update | macOS Catalina 10.15.5 Supplemental Update |
| apple | tvos | < 13.4.6 | 13.4.6 |
| apple | tvos | >= unspecified < tvOS 13.4.6 | tvOS 13.4.6 |
| apple | watchos | < 6.2.6 | 6.2.6 |
| apple | watchos | >= unspecified < watchOS 6.2.6 | watchOS 6.2.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-frwv-8c9x-7766: A memory consumption issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2020-9859 [HIGH] CWE-400 GHSA-frwv-8c9x-7766: A memory consumption issue was addressed with improved memory handling
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
VulnCheck
Apple Multiple Products Code Execution Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-9859 [HIGH] CWE-415 Apple Multiple Products Code Execution Vulnerability
Apple Multiple Products Code Execution Vulnerability
Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.
Affected: Apple Multiple Products
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-03
CISA
Apple Multiple Products Code Execution Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-9859 [HIGH] CWE-415 Apple Multiple Products Code Execution Vulnerability
Vulnerability: Apple Multiple Products Code Execution Vulnerability
Affected: Apple Multiple Products
Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-9859
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-05
Published
2021-11-03
Added to CISA KEV
Exploited in the wild