cbcvebase.
CVE-2020-9934
published 2020-10-16

CVE-2020-9934: An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6…

PriorityP277medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-09-29
Exploited in the wild
EPSS
3.21%
86.7th percentile
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.

Affected

7 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.6 and iPadOS 13.6iOS 13.6 and iPadOS 13.6
appleios_13.6_and_ipados
appleipados< 13.613.6
appleiphone_os< 13.613.6
applemac_os_x< 10.15.610.15.6
applemacos>= unspecified < macOS Catalina 10.15.6macOS Catalina 10.15.6
applemacos_catalina_10.15.6_security_update_2020-004_mojave_security_update_2020-004

Detection & IOCsextracted from sources · hover to see the quote

  • The TCC daemon can be manipulated by setting the HOME environment variable to a user-controlled location, causing tccd to use an attacker-supplied TCC database instead of the legitimate one. Monitor for unusual HOME environment variable values set in processes spawned under tccd or its children.
  • Monitor for INSERT operations into a user-controlled TCC database file (e.g., TCC.db in a non-standard HOME path) that grant TCC entitlements to arbitrary processes.
  • The vulnerable component is CoreFoundation on macOS Catalina <= 10.15.5, iOS 13.x, and iPadOS 13.x. Scope detection efforts to these platform/version combinations.
  • ·This is a local privilege/entitlement escalation vulnerability; exploitation requires local user access. Remote exploitation is not applicable.
  • ·The affected component is CoreFoundation (TCC daemon, tccd). Detections should be scoped to macOS Catalina <= 10.15.5, iOS <= 13.5, and iPadOS <= 13.5, as the fix was introduced in macOS Catalina 10.15.6, iOS 13.6, and iPadOS 13.6.

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vulncheck5.5MEDIUM
cisa5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.