cbcvebase.
CVE-2020-9907
published 2020-10-16

CVE-2020-9907: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be…

PriorityP181high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
3.90%
89.2th percentile
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.

Affected

7 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.6 and iPadOS 13.6iOS 13.6 and iPadOS 13.6
appleios_13.6_and_ipados
appleipados< 13.613.6
appleiphone_os< 13.613.6
appletvos< 13.4.813.4.8
appletvos
appletvos>= unspecified < tvOS 13.4.8tvOS 13.4.8

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerable component is AVEVideoEncoder kernel extension on iOS/iPadOS/tvOS; monitor for unexpected privilege escalation or kernel-level code execution originating from applications interacting with AVEVideoEncoder
  • Target platforms are iOS/iPadOS prior to 13.6 and tvOS prior to 13.4.8; unpatched devices should be flagged in asset inventory for prioritized patching
  • CVE-2020-9907 is listed as a Known Exploited Vulnerability by CISA, indicating active in-the-wild exploitation; treat any unpatched Apple iOS/iPadOS/tvOS device as high-priority risk
  • ·The fix was implemented by removing the vulnerable code entirely from AVEVideoEncoder, not by patching logic; detection should focus on pre-patch OS versions rather than specific code patterns

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.