CVE-2020-9934
published 2020-10-16CVE-2020-9934: An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6…
PriorityP277medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-09-29
Exploited in the wild
EPSS
3.21%
86.7th percentile
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < iOS 13.6 and iPadOS 13.6 | iOS 13.6 and iPadOS 13.6 |
| apple | ios_13.6_and_ipados | — | — |
| apple | ipados | < 13.6 | 13.6 |
| apple | iphone_os | < 13.6 | 13.6 |
| apple | mac_os_x | < 10.15.6 | 10.15.6 |
| apple | macos | >= unspecified < macOS Catalina 10.15.6 | macOS Catalina 10.15.6 |
| apple | macos_catalina_10.15.6_security_update_2020-004_mojave_security_update_2020-004 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The TCC daemon can be manipulated by setting the HOME environment variable to a user-controlled location, causing tccd to use an attacker-supplied TCC database instead of the legitimate one. Monitor for unusual HOME environment variable values set in processes spawned under tccd or its children. ↗
- →Monitor for INSERT operations into a user-controlled TCC database file (e.g., TCC.db in a non-standard HOME path) that grant TCC entitlements to arbitrary processes. ↗
- →The vulnerable component is CoreFoundation on macOS Catalina <= 10.15.5, iOS 13.x, and iPadOS 13.x. Scope detection efforts to these platform/version combinations. ↗
- ·This is a local privilege/entitlement escalation vulnerability; exploitation requires local user access. Remote exploitation is not applicable. ↗
- ·The affected component is CoreFoundation (TCC daemon, tccd). Detections should be scoped to macOS Catalina <= 10.15.5, iOS <= 13.5, and iPadOS <= 13.5, as the fix was introduced in macOS Catalina 10.15.6, iOS 13.6, and iPadOS 13.6. ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vulncheck5.5MEDIUM
cisa5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple iOS, iPadOS, and macOS Input Validation Vulnerability
cisa·2022-09-08·CVSS 5.5
CVE-2020-9934 [MEDIUM] Apple iOS, iPadOS, and macOS Input Validation Vulnerability
Vulnerability: Apple iOS, iPadOS, and macOS Input Validation Vulnerability
Affected: Apple iOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information.
Required Action: Apply updates per vendor instructions.
Notes: https://support.apple.com/en-us/HT211288, https://support.apple.com/en-us/HT211289; https://nvd.nist.gov/vuln/detail/CVE-2020-9934
Remediation Due Date: 2022-09-29
Apple
CVE-2020-9934: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
vendor_apple·2020-07-15·CVSS 5.5
CVE-2020-9934 [MEDIUM] CVE-2020-9934: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
Product: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
CVE: CVE-2020-9934
Component: CoreFoundation
Impact: A local user may be able to view sensitive user information
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Apple
CVE-2020-9934: iOS 13.6 and iPadOS 13.6
vendor_apple·2020-07-15·CVSS 5.5
CVE-2020-9934 [MEDIUM] CVE-2020-9934: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9934
Component: CoreFoundation
Impact: A local user may be able to view sensitive user information
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
GHSA
GHSA-x5m3-93g8-f3rh: An issue existed in the handling of environment variables
ghsa_unreviewed·2022-05-24
CVE-2020-9934 [MEDIUM] GHSA-x5m3-93g8-f3rh: An issue existed in the handling of environment variables
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.
VulnCheck
Apple iOS, iPadOS, and macOS Input Validation Vulnerability
vulncheck·2020·CVSS 5.5
CVE-2020-9934 [MEDIUM] Apple iOS, iPadOS, and macOS Input Validation Vulnerability
Apple iOS, iPadOS, and macOS Input Validation Vulnerability
Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information.
Affected: Apple iOS, iPadOS, and macOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/c44c15bdb861
Remediation Due: 2022-09-29
No detection rules found.
2020-10-16
Published
2022-09-08
Added to CISA KEV
Exploited in the wild