CVE-2021-30869
published 2021-08-24CVE-2021-30869: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security…
PriorityP181high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
4.15%
89.8th percentile
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios_14.4_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 14.4 | 14.4 |
| apple | ipados | < 14.4 | 14.4 |
| apple | iphone_os | >= 12.0 < 12.5.5 | 12.5.5 |
| apple | iphone_os | >= 14.0 < 14.4 | 14.4 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | 10.14 – 10.14.6 | — |
| apple | mac_os_x | 10.15 – 10.15.6 | — |
| apple | macos | >= 11.0 < 11.2 | 11.2 |
| apple | macos | >= unspecified < 11.2 | 11.2 |
| apple | macos | >= unspecified < 12.5 | 12.5 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos_big_sur_11.2_security_update_2021-001_catalina_security_update_2021-001_mo | — | — |
| apple | security_update_2021-006_catalina | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →OSX.DazzleSpy exploits CVE-2021-30869 (XNU type confusion, kernel privilege escalation) as part of a watering-hole attack chain targeting Hong Kong pro-democracy activist websites; look for the DazzleSpy payload being executed as root following browser exploitation. ↗
- →Presence of the hidden directory .Documenty (note deliberate misspelling) containing keystealDaemon, libkeystealClient.dylib, or security-unsigned is a strong indicator of DazzleSpy activity. ↗
- →DazzleSpy is an unsigned Mach-O compiled for Intel x86; alert on unsigned Mach-O binaries executing from ~/.local/ or .Documenty/ paths. ↗
- →Network connections to 88.218.192.128 on port 5633 are indicative of active DazzleSpy C2 communication. ↗
- ·CVE-2021-30869 is a kernel-level type confusion bug in XNU; exploitation requires a malicious application already running on the device — it is a local privilege escalation, not a remote code execution vector by itself. ↗
- ·The vulnerability affects a wide range of older Apple hardware (iPhone 5s through iPhone 6 Plus, iPad Air, iPad mini 2/3, iPod touch 6th gen) running iOS 12 as well as macOS Big Sur, Catalina, and Mojave; patched in iOS 12.5.5 and macOS Big Sur 11.2 / Security Update 2021-001. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2021-30869 [HIGH] CWE-843 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
Vulnerability: Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
Affected: Apple iOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-30869
Remediation Due Date: 2021-11-17
Apple
CVE-2021-30869: iOS 12.5.5
vendor_apple·2021-09-23·CVSS 7.8
CVE-2021-30869 [HIGH] CVE-2021-30869: iOS 12.5.5
Apple Security Update: About the security content of iOS 12.5.5
Product: iOS
Version: 12.5.5
CVE: CVE-2021-30869
Component: XNU
Impact: A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.
Description: A type confusion issue was addressed with improved state handling.
Apple
CVE-2021-30869: Security Update 2021-006 Catalina
vendor_apple·2021-09-23·CVSS 7.8
CVE-2021-30869 [HIGH] CVE-2021-30869: Security Update 2021-006 Catalina
Apple Security Update: About the security content of Security Update 2021-006 Catalina
Product: Security Update 2021-006 Catalina
CVE: CVE-2021-30869
Component: XNU
Impact: A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.
Description: A type confusion issue was addressed with improved state handling.
Apple
CVE-2021-30869: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
vendor_apple·2021-02-01·CVSS 7.8
CVE-2021-30869 [HIGH] CVE-2021-30869: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
Apple Security Update: About the security content of macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
Product: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
CVE: CVE-2021-30869
Component: XNU
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A type confusion issue was addressed with improved state handling.
Apple
CVE-2021-30869: iOS 14.4 and iPadOS 14.4
vendor_apple·2021-01-26·CVSS 7.8
CVE-2021-30869 [HIGH] CVE-2021-30869: iOS 14.4 and iPadOS 14.4
Apple Security Update: About the security content of iOS 14.4 and iPadOS 14.4
Product: iOS 14.4 and iPadOS
Version: 14.4
CVE: CVE-2021-30869
Component: XNU
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A type confusion issue was addressed with improved state handling.
Project0
The More You Know, The More You Know You Don’t Know - Project Zero
project_zero·2022-04-01
CVE-2016-4654 The More You Know, The More You Know You Don’t Know - Project Zero
A Year in Review of 0-days Used In-the-Wild in 2021
Posted by Maddie Stone, Google Project Zero
This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019]. Each year we’ve looked back at all of the detected and disclosed in-the-wild 0-days as a group and synthesized what we think the trends and takeaways are. The goal of this report is not to detail each individual exploit, but instead to analyze the exploits from the year as a group, looking for trends, gaps, lessons learned, successes, etc. If you’re interested in the analysis of individual exploits, please check out our root cause analysis repository.
We perform and share this analysis in order to make 0-day hard. We want it to be more costly, more resource intensive, and overall more difficult for
VulnCheck
Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-30869 [HIGH] CWE-843 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
Affected: Apple iOS, iPadOS, and macOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.welivesecurity.com/2022/01/25/watering-hole-deploys-new-macos-malware-dazzlespy-asia/; https://objective-see.org/blog/blog_0x71.html; https://www.group-ib.com/resources/resea
No detection rules found.
No public exploits indexed.
Sentinelone
7 Ways Threat Actors Deliver macOS Malware in the Enterprise
blogs_sentinelone·2023-01-09
7 Ways Threat Actors Deliver macOS Malware in the Enterprise
Our 2022 review of macOS malware revealed that the threats faced by businesses and users running macOS endpoints included an increase in backdoors and cross-platform attack frameworks. Threats like CrateDepression and PyMafka used typosquatting attacks against package repositories to infect users, while ChromeLoader and others like oRAT leveraged malvertising as an infection vector.
However, the infection vector used by many other macOS threats remains unknown. SysJoker, OSX.Gimmick, CloudMensis, Alchimist and the Lazarus-attributed Operation In(ter)ception are just some of those for which researchers still do not know how victims were initially compromised. In these and other cases, researchers happened across the malware either in post-infection analyses or by discovering the samples on
Sentinelone
7 Ways Threat Actors Deliver macOS Malware in the Enterprise
blogs_sentinelone·2023-01-09
7 Ways Threat Actors Deliver macOS Malware in the Enterprise
Our 2022 review of macOS malware revealed that the threats faced by businesses and users running macOS endpoints included an increase in backdoors and cross-platform attack frameworks. Threats like CrateDepression and PyMafka used typosquatting attacks against package repositories to infect users, while ChromeLoader and others like oRAT leveraged malvertising as an infection vector.
However, the infection vector used by many other macOS threats remains unknown. SysJoker , OSX.Gimmick, CloudMensis, Alchimist and the Lazarus-attributed Operation In(ter)ception are just some of those for which researchers still do not know how victims were initially compromised. In these and other cases, researchers happened across the malware either in post-infection analyses or by discovering the samples o
Sentinelone
How SysJoker and DazzleSpy Malware Target macOS
blogs_sentinelone·2022-02-01
How SysJoker and DazzleSpy Malware Target macOS
As last year closed out, we provided a round up of the previous 12 months of Mac malware , making the observation that, among other things, 2021’s macOS malware cohort saw a focus on spyware and the targeting of users in Asia, particularly China and Hong Kong. The first month of 2022 has seen those trends continue with two new malware campaigns discovered in January, namely SysJoker and DazzleSpy.
In this post, we give brief overviews of these two new malware families, offering both additional details not previously reported along with indicators for detection and threat hunting.
## SysJoker (11th Jan, 2022)
The first new Mac malware report of 2022 came courtesy of researchers at Intezer in the form of a threat they dubbed SysJoker , which comes in Windows, Linux and macOS variants. Res
Sentinelone
How SysJoker and DazzleSpy Malware Target macOS
blogs_sentinelone·2022-02-01
How SysJoker and DazzleSpy Malware Target macOS
As last year closed out, we provided a round up of the previous 12 months of Mac malware, making the observation that, among other things, 2021’s macOS malware cohort saw a focus on spyware and the targeting of users in Asia, particularly China and Hong Kong. The first month of 2022 has seen those trends continue with two new malware campaigns discovered in January, namely SysJoker and DazzleSpy.
In this post, we give brief overviews of these two new malware families, offering both additional details not previously reported along with indicators for detection and threat hunting.
## SysJoker (11th Jan, 2022)
The first new Mac malware report of 2022 came courtesy of researchers at Intezer in the form of a threat they dubbed SysJoker, which comes in Windows, Linux and macOS variants. Resea
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “ Apple is aware of a report that this issue may have been actively exploited ,” the company said in security advisories .
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited . Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vul
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “Apple is aware of a report that this issue may have been actively exploited,” the company said in security advisories.
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited. Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vulnera
Qualys
NSO Pegasus iPhone Spyware Vulnerabilities Fixed by Apple - Detect & Prioritize Using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-09-29·CVSS 8.8
[HIGH] NSO Pegasus iPhone Spyware Vulnerabilities Fixed by Apple - Detect & Prioritize Using VMDR for Mobile Devices | Qualys
#### Table of Contents
- CoreGraphics Arbitrary Code Execution Vulnerability
- WebKit Arbitrary Code Execution Vulnerability
- XNU Arbitrary Code Execution with Kernel Privileges Vulnerability
- Multiple ImageIO Arbitrary Code Execution Vulnerabilities
- Discover Vulnerabilities and Take Remote Response Action Using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 12.5.5, 15.0, which includes a security update that addresses almost 25 vulnerabilities, including several critical RCE and privilege escalation vulnerabilities. In 12.5.5, Apple fixed 3 critical zero-day vulnerabilities, which are used to deploy NSO Pegasus iPhone spyware to secure old iPhones. Earlier in 14.8 these 2 critical zero-day vulnerabilities exploited by NSO Pegasus were fixed and on 20th September Appl
Qualys
NSO Pegasus iPhone Spyware Vulnerabilities Fixed by Apple – Detect & Prioritize Using VMDR for Mobile Devices
blogs_qualys·2021-09-29·CVSS 8.8
[HIGH] NSO Pegasus iPhone Spyware Vulnerabilities Fixed by Apple – Detect & Prioritize Using VMDR for Mobile Devices
## Table of Contents
CoreGraphics Arbitrary Code Execution Vulnerability
WebKit Arbitrary Code Execution Vulnerability
XNU Arbitrary Code Execution with Kernel Privileges Vulnerability
Multiple ImageIO Arbitrary Code Execution Vulnerabilities
Discover Vulnerabilities and Take Remote Response Action Using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 12.5.5 , 15.0 , which includes a security update that addresses almost 25 vulnerabilities, including several critical RCE and privilege escalation vulnerabilities. In 12.5.5, Apple fixed 3 critical zero-day vulnerabilities, which are used to deploy NSO Pegasus iPhone spyware to secure old iPhones. Earlier in 14.8 these 2 critical zero-day vulnerabilities exploited by NSO Pegasus were fixed and on 20 th September Apple upd
https://support.apple.com/en-us/HT212146https://support.apple.com/en-us/HT212147https://support.apple.com/en-us/HT212824https://support.apple.com/en-us/HT212825https://support.apple.com/en-us/HT212146https://support.apple.com/en-us/HT212147https://support.apple.com/en-us/HT212824https://support.apple.com/en-us/HT212825https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30869
2021-08-24
Published
2021-11-03
Added to CISA KEV
Exploited in the wild