CVE-2020-9907
published 2020-10-16CVE-2020-9907: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be…
PriorityP181high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
3.90%
89.1th percentile
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < iOS 13.6 and iPadOS 13.6 | iOS 13.6 and iPadOS 13.6 |
| apple | ios_13.6_and_ipados | — | — |
| apple | ipados | < 13.6 | 13.6 |
| apple | iphone_os | < 13.6 | 13.6 |
| apple | tvos | < 13.4.8 | 13.4.8 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < tvOS 13.4.8 | tvOS 13.4.8 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable component is AVEVideoEncoder kernel extension on iOS/iPadOS/tvOS; monitor for unexpected privilege escalation or kernel-level code execution originating from applications interacting with AVEVideoEncoder ↗
- →Target platforms are iOS/iPadOS prior to 13.6 and tvOS prior to 13.4.8; unpatched devices should be flagged in asset inventory for prioritized patching ↗
- →CVE-2020-9907 is listed as a Known Exploited Vulnerability by CISA, indicating active in-the-wild exploitation; treat any unpatched Apple iOS/iPadOS/tvOS device as high-priority risk ↗
- ·The fix was implemented by removing the vulnerable code entirely from AVEVideoEncoder, not by patching logic; detection should focus on pre-patch OS versions rather than specific code patterns ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple Multiple Products Memory Corruption Vulnerability
cisa·2022-06-27·CVSS 7.8
CVE-2020-9907 [HIGH] CWE-787 Apple Multiple Products Memory Corruption Vulnerability
Vulnerability: Apple Multiple Products Memory Corruption Vulnerability
Affected: Apple Multiple Products
Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-9907
Remediation Due Date: 2022-07-18
Apple
CVE-2020-9907: iOS 13.6 and iPadOS 13.6
vendor_apple·2020-07-15·CVSS 7.8
CVE-2020-9907 [HIGH] CVE-2020-9907: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9907
Component: AVEVideoEncoder
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
Apple
CVE-2020-9907: tvOS 13.4.8
vendor_apple·2020-07-15·CVSS 7.8
CVE-2020-9907 [HIGH] CVE-2020-9907: tvOS 13.4.8
Apple Security Update: About the security content of tvOS 13.4.8
Product: tvOS
Version: 13.4.8
CVE: CVE-2020-9907
Component: AVEVideoEncoder
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed by removing the vulnerable code.
GHSA
GHSA-x2gp-c4cv-7chc: A memory corruption issue was addressed by removing the vulnerable code
ghsa_unreviewed·2022-05-24
CVE-2020-9907 [HIGH] CWE-119 GHSA-x2gp-c4cv-7chc: A memory corruption issue was addressed by removing the vulnerable code
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.
VulnCheck
Apple Multiple Products Memory Corruption Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-9907 [HIGH] CWE-787 Apple Multiple Products Memory Corruption Vulnerability
Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
Affected: Apple Multiple Products
Required Action: Apply updates per vendor instructions.
Exploitation References: https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-07-18
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-16
Published
2022-06-27
Added to CISA KEV
Exploited in the wild