CVE-2021-30712
published 2021-09-08CVE-2021-30712: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.77%
88.8th percentile
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | 10.14 – 10.14.5 | — |
| apple | mac_os_x | 10.15 – 10.15.6 | — |
| apple | macos | >= 11.0 < 11.4 | 11.4 |
| apple | macos | >= unspecified < 11.4 | 11.4 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-003_catalina | — | — |
| apple | security_update_2021-004_mojave | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-30712: Security Update 2021-004 Mojave
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30712 [HIGH] CVE-2021-30712: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30712
Component: Security
Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code
Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
Apple
CVE-2021-30712: macOS Big Sur 11.4
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30712 [HIGH] CVE-2021-30712: macOS Big Sur 11.4
Apple Security Update: About the security content of macOS Big Sur 11.4
Product: macOS Big Sur
Version: 11.4
CVE: CVE-2021-30712
Component: Security
Impact: Processing a maliciously crafted certificate may lead to arbitrary code execution
Description: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code.
Apple
CVE-2021-30712: Security Update 2021-003 Catalina
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30712 [HIGH] CVE-2021-30712: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30712
Component: Security
Impact: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code
Description: Processing a maliciously crafted certificate may lead to arbitrary code execution.
GHSA
GHSA-6qh5-cp9g-4x2r: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2021-30712 [HIGH] GHSA-6qh5-cp9g-4x2r: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: A deep dive into macOS SMB server
blogs_talos·2021-06-02
Vulnerability Spotlight: A deep dive into macOS SMB server
By Aleksandar Nikolich.
## Executive summary
Cisco Talos recently discovered multiple vulnerabilities in macOS’s implementation of SMB server. An adversary could exploit these vulnerabilities to carry out a variety of malicious actions, including revealing sensitive information on the server, bypassing certain cryptographic checks, causing a denial of service or execute remote code on the targeted server. Cisco Talos worked with Apple to ensure that these issues are resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy. Users are encouraged to update to the latest macOS version as soon as possible to patch these vulnerabilities.
## Background
SMB is among the most ubiquitous network protocols encountered in enterprise en
Talos
Vulnerability Spotlight: A deep dive into macOS SMB server
blogs_talos·2021-06-02
Vulnerability Spotlight: A deep dive into macOS SMB server
## Vulnerability Spotlight: A deep dive into macOS SMB server
By Aleksandar Nikolich.
## Executive summary
Cisco Talos recently discovered multiple vulnerabilities in macOS’s implementation of SMB server. An adversary could exploit these vulnerabilities to carry out a variety of malicious actions, including revealing sensitive information on the server, bypassing certain cryptographic checks, causing a denial of service or execute remote code on the targeted server. Cisco Talos worked with Apple to ensure that these issues are resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy. Users are encouraged to update to the latest macOS version as soon as possible to patch these vulnerabilities.
## Background
SMB is among the
2021-09-08
Published