CVE-2021-30724
published 2021-09-08CVE-2021-30724: This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.81%
53.1th percentile
This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local attacker may be able to elevate their privileges.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | >= unspecified < 14.6 | 14.6 |
| apple | ipados | < 14.6 | 14.6 |
| apple | iphone_os | < 14.6 | 14.6 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | 10.14.0 – 10.14.5 | — |
| apple | mac_os_x | 10.15 – 10.15.6 | — |
| apple | macos | >= 11.0.1 < 11.4 | 11.4 |
| apple | macos | >= unspecified < 11.4 | 11.4 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos | >= unspecified < 14.6 | 14.6 |
| apple | macos | >= unspecified < 7.5 | 7.5 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-003_catalina | — | — |
| apple | security_update_2021-004_mojave | — | — |
| apple | tvos | — | — |
| apple | watchos | < 7.5 | 7.5 |
| apple | watchos | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-30724: watchOS 7.5
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: watchOS 7.5
Apple Security Update: About the security content of watchOS 7.5
Product: watchOS
Version: 7.5
CVE: CVE-2021-30724
Component: CVMS
Impact: A local attacker may be able to elevate their privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2021-30724: Security Update 2021-004 Mojave
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: Security Update 2021-004 Mojave
Apple Security Update: About the security content of Security Update 2021-004 Mojave
Product: Security Update 2021-004 Mojave
CVE: CVE-2021-30724
Component: CVMS
Impact: A local attacker may be able to elevate their privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2021-30724: macOS Big Sur 11.4
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: macOS Big Sur 11.4
Apple Security Update: About the security content of macOS Big Sur 11.4
Product: macOS Big Sur
Version: 11.4
CVE: CVE-2021-30724
Component: CVMS
Impact: A local attacker may be able to elevate their privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2021-30724: tvOS 14.6
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: tvOS 14.6
Apple Security Update: About the security content of tvOS 14.6
Product: tvOS
Version: 14.6
CVE: CVE-2021-30724
Component: CVMS
Impact: A local attacker may be able to elevate their privileges
Description: This issue was addressed with improved checks.
Apple
CVE-2021-30724: Security Update 2021-003 Catalina
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: Security Update 2021-003 Catalina
Apple Security Update: About the security content of Security Update 2021-003 Catalina
Product: Security Update 2021-003 Catalina
CVE: CVE-2021-30724
Component: CVMS
Impact: A local attacker may be able to elevate their privileges
Description: This issue was addressed with improved checks.
GHSA
GHSA-4f77-xqjh-98gr: This issue was addressed with improved checks
ghsa_unreviewed·2022-05-24
CVE-2021-30724 [HIGH] CWE-269 GHSA-4f77-xqjh-98gr: This issue was addressed with improved checks
This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local attacker may be able to elevate their privileges.
No detection rules found.
No public exploits indexed.
Trendmicro
This Week in Security News June 4, 2021
blogs_trendmicro·2021-06-04
This Week in Security News June 4, 2021
Cyber Crime
# This Week in Security News June 4, 2021
Cyberattack hits JBS meat works in Australia, North America and DarkSide Targets Virtual Machines
By: Jon Clay
2021/06/04
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, read about how the world’s largest meatpacker, JBS, was the target of an organized cybersecurity attack. Also, learn how a DarkSide ransomware variant is targeting virtual machine-related files on VMware ESXI servers.
Read on:
Where Bug Bounty Programs Fall Flat
Cybercriminal forums shows that cybercriminals have specific preferences, shown by the exploits they requisition, and that bug bounty programs either are too slow, d
Trendmicro
CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
blogs_trendmicro·2021-06-03·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
Exploits y vulnerabilidades
## CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
We discovered a vulnerability in macOS, iOS, and iPadOS rooted in the CVMServer. The vulnerability, labeled CVE-2021-30724, can allow threat actors to escalate their privilege if exploited.
By: Mickey Jin Jun 03, 2021 Read time: ( words)
Save to Folio
We discovered a vulnerability in macOS rooted in the Core Virtual Machine Server (CVMServer). The vulnerability, labeled CVE-2021-30724 , is triggered by an integer overflow leading to an out-of-bounds memory access, from which point privilege escalation can be attained. It affects devices running older versions of macOS Big Sur 11.4, iOS 14.6, and iPadOS 14.6.
This issue has already been fixed by Apple at the time of writing. This blog entry details
Trendmicro
CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
blogs_trendmicro·2021-06-03·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
Exploits & Vulnerabilities
## CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
We discovered a vulnerability in macOS, iOS, and iPadOS rooted in the CVMServer. The vulnerability, labeled CVE-2021-30724, can allow threat actors to escalate their privilege if exploited.
By: Mickey Jin Jun 03, 2021 Read time: ( words)
Save to Folio
We discovered a vulnerability in macOS rooted in the Core Virtual Machine Server (CVMServer). The vulnerability, labeled CVE-2021-30724 , is triggered by an integer overflow leading to an out-of-bounds memory access, from which point privilege escalation can be attained. It affects devices running older versions of macOS Big Sur 11.4, iOS 14.6, and iPadOS 14.6.
This issue has already been fixed by Apple at the time of writing. This blog entry details
Trendmicro
CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
blogs_trendmicro·2021-06-03·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
Ausnutzung von Schwachstellen
## CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
We discovered a vulnerability in macOS, iOS, and iPadOS rooted in the CVMServer. The vulnerability, labeled CVE-2021-30724, can allow threat actors to escalate their privilege if exploited.
By: Mickey Jin Jun 03, 2021 Read time: ( words)
Save to Folio
We discovered a vulnerability in macOS rooted in the Core Virtual Machine Server (CVMServer). The vulnerability, labeled CVE-2021-30724 , is triggered by an integer overflow leading to an out-of-bounds memory access, from which point privilege escalation can be attained. It affects devices running older versions of macOS Big Sur 11.4, iOS 14.6, and iPadOS 14.6.
This issue has already been fixed by Apple at the time of writing. This blog entry detai
Trendmicro
CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
blogs_trendmicro·2021-06-03·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
Exploits & Vulnerabilities
# CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
We discovered a vulnerability in macOS, iOS, and iPadOS rooted in the CVMServer. The vulnerability, labeled CVE-2021-30724, can allow threat actors to escalate their privilege if exploited.
By: Mickey Jin
2021/06/03
Read time: ( words)
Save to Folio
We discovered a vulnerability in macOS rooted in the Core Virtual Machine Server (CVMServer). The vulnerability, labeled CVE-2021-30724, is triggered by an integer overflow leading to an out-of-bounds memory access, from which point privilege escalation can be attained. It affects devices running older versions of macOS Big Sur 11.4, iOS 14.6, and iPadOS 14.6.
This issue has already been fixed by Apple at the time of writing. This blog entry details whe
Trendmicro
CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
blogs_trendmicro·2021-06-03·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
Sfruttamento vulnerabilità
## CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
We discovered a vulnerability in macOS, iOS, and iPadOS rooted in the CVMServer. The vulnerability, labeled CVE-2021-30724, can allow threat actors to escalate their privilege if exploited.
By: Mickey Jin Jun 03, 2021 Read time: ( words)
Save to Folio
We discovered a vulnerability in macOS rooted in the Core Virtual Machine Server (CVMServer). The vulnerability, labeled CVE-2021-30724 , is triggered by an integer overflow leading to an out-of-bounds memory access, from which point privilege escalation can be attained. It affects devices running older versions of macOS Big Sur 11.4, iOS 14.6, and iPadOS 14.6.
This issue has already been fixed by Apple at the time of writing. This blog entry details
Trendmicro
CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
blogs_trendmicro·2021-06-03·CVSS 7.8
CVE-2021-30724 [HIGH] CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
Exploits & Vulnerabilities
## CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
We discovered a vulnerability in macOS, iOS, and iPadOS rooted in the CVMServer. The vulnerability, labeled CVE-2021-30724, can allow threat actors to escalate their privilege if exploited.
By: Mickey Jin 2021/06/03 Read time: ( words)
Save to Folio
We discovered a vulnerability in macOS rooted in the Core Virtual Machine Server (CVMServer). The vulnerability, labeled CVE-2021-30724 , is triggered by an integer overflow leading to an out-of-bounds memory access, from which point privilege escalation can be attained. It affects devices running older versions of macOS Big Sur 11.4, iOS 14.6, and iPadOS 14.6.
This issue has already been fixed by Apple at the time of writing. This blog entry details wh
https://support.apple.com/en-us/HT212528https://support.apple.com/en-us/HT212529https://support.apple.com/en-us/HT212530https://support.apple.com/en-us/HT212531https://support.apple.com/en-us/HT212532https://support.apple.com/en-us/HT212533https://support.apple.com/en-us/HT212528https://support.apple.com/en-us/HT212529https://support.apple.com/en-us/HT212530https://support.apple.com/en-us/HT212531https://support.apple.com/en-us/HT212532https://support.apple.com/en-us/HT212533
2021-09-08
Published