CVE-2021-30855
published 2021-08-24CVE-2021-30855: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update…
PriorityP427medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
2.40%
82.2th percentile
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. An application may be able to access restricted files.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_14.8_and_ipados | — | — |
| apple | ios_15_and_ipados | — | — |
| apple | ipados | < 14.8 | 14.8 |
| apple | iphone_os | < 14.8 | 14.8 |
| apple | mac_os_x | < 10.15.7 | 10.15.7 |
| apple | mac_os_x | — | — |
| apple | macos | < 11.6 | 11.6 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos | >= unspecified < 14.8 | 14.8 |
| apple | macos | >= unspecified < 15 | 15 |
| apple | macos | >= unspecified < 8 | 8 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-005_catalina | — | — |
| apple | tvos | < 15.0 | 15.0 |
| apple | tvos | — | — |
| apple | watchos | < 8.0 | 8.0 |
| apple | watchos_8 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-30855: watchOS 8
vendor_apple·2021-09-20·CVSS 5.5
CVE-2021-30855 [MEDIUM] CVE-2021-30855: watchOS 8
Apple Security Update: About the security content of watchOS 8
Product: watchOS 8
CVE: CVE-2021-30855
Component: Preferences
Impact: An application may be able to access restricted files
Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Apple
CVE-2021-30855: tvOS 15
vendor_apple·2021-09-20·CVSS 5.5
CVE-2021-30855 [MEDIUM] CVE-2021-30855: tvOS 15
Apple Security Update: About the security content of tvOS 15
Product: tvOS
Version: 15
CVE: CVE-2021-30855
Component: Preferences
Impact: An application may be able to access restricted files
Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Apple
CVE-2021-30855: iOS 15 and iPadOS 15
vendor_apple·2021-09-20·CVSS 5.5
CVE-2021-30855 [MEDIUM] CVE-2021-30855: iOS 15 and iPadOS 15
Apple Security Update: About the security content of iOS 15 and iPadOS 15
Product: iOS 15 and iPadOS
Version: 15
CVE: CVE-2021-30855
Component: Preferences
Impact: An application may be able to access restricted files
Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Apple
CVE-2021-30855: Security Update 2021-005 Catalina
vendor_apple·2021-09-13·CVSS 5.5
CVE-2021-30855 [MEDIUM] CVE-2021-30855: Security Update 2021-005 Catalina
Apple Security Update: About the security content of Security Update 2021-005 Catalina
Product: Security Update 2021-005 Catalina
CVE: CVE-2021-30855
Component: Preferences
Impact: An application may be able to access restricted files
Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Apple
CVE-2021-30855: iOS 14.8 and iPadOS 14.8
vendor_apple·2021-09-13·CVSS 5.5
CVE-2021-30855 [MEDIUM] CVE-2021-30855: iOS 14.8 and iPadOS 14.8
Apple Security Update: About the security content of iOS 14.8 and iPadOS 14.8
Product: iOS 14.8 and iPadOS
Version: 14.8
CVE: CVE-2021-30855
Component: Preferences
Impact: An application may be able to access restricted files
Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Apple
CVE-2021-30855: macOS Big Sur 11.6
vendor_apple·2021-09-13·CVSS 5.5
CVE-2021-30855 [MEDIUM] CVE-2021-30855: macOS Big Sur 11.6
Apple Security Update: About the security content of macOS Big Sur 11.6
Product: macOS Big Sur
Version: 11.6
CVE: CVE-2021-30855
Component: Preferences
Impact: An application may be able to access restricted files
Description: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
No detection rules found.
No public exploits indexed.
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits & Vulnerabilities
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin Jan 14, 2022 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits & Vulnerabilities
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin 2022/01/14 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in ea
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Sfruttamento vulnerabilità
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin Jan 14, 2022 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits y vulnerabilidades
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin Jan 14, 2022 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits & Vulnerabilities
# Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin
2022/01/14
Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740, which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in ear
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Ausnutzung von Schwachstellen
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin Jan 14, 2022 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However,
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits & Vulnerabilities
# Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin
Jan 14, 2022
Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740, which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in e
https://support.apple.com/en-us/HT212804https://support.apple.com/en-us/HT212805https://support.apple.com/en-us/HT212807https://support.apple.com/en-us/HT212814https://support.apple.com/en-us/HT212819https://support.apple.com/kb/HT212815https://support.apple.com/en-us/HT212804https://support.apple.com/en-us/HT212805https://support.apple.com/en-us/HT212807https://support.apple.com/en-us/HT212814https://support.apple.com/en-us/HT212819https://support.apple.com/kb/HT212815
2021-08-24
Published