CVE-2020-9922Apple Macos vulnerability

4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.4%
top 38.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateMay 24

Description

A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. Processing a maliciously crafted email may lead to writing arbitrary files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5apple/macosunspecified10.15
NVDapple/mac_os_x< 10.15.6

🔴Vulnerability Details

2
GHSA
GHSA-wxpj-m284-3v3q: A logic issue was addressed with improved state management2022-05-24
CVEList
CVE-2020-9922: A logic issue was addressed with improved state management2020-12-08

📋Vendor Advisories

1
Apple
CVE-2020-9922: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra2020-07-15
CVE-2020-9922 — Apple Macos vulnerability | cvebase