CVE-2021-30995
published 2021-08-24CVE-2021-30995: A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update…
PriorityP431high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
2.31%
81.5th percentile
A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to elevate privileges.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | >= unspecified < 15.2 | 15.2 |
| apple | ipados | < 15.2 | 15.2 |
| apple | iphone_os | < 15.2 | 15.2 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.6.2 | 11.6.2 |
| apple | macos | >= 12.0 < 12.1 | 12.1 |
| apple | macos | >= unspecified < 12.1 | 12.1 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos | >= unspecified < 15.2 | 15.2 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2021-008_catalina | — | — |
| apple | tvos | < 15.2 | 15.2 |
| apple | tvos | — | — |
| apple | watchos | < 8.3 | 8.3 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.3 | 8.3 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-30995: Security Update 2021-008 Catalina
vendor_apple·2021-12-13·CVSS 7.0
CVE-2021-30995 [HIGH] CVE-2021-30995: Security Update 2021-008 Catalina
Apple Security Update: About the security content of Security Update 2021-008 Catalina
Product: Security Update 2021-008 Catalina
CVE: CVE-2021-30995
Component: Preferences
Impact: A malicious application may be able to elevate privileges
Description: A race condition was addressed with improved state handling.
Apple
CVE-2021-30995: watchOS 8.3
vendor_apple·2021-12-13·CVSS 7.0
CVE-2021-30995 [HIGH] CVE-2021-30995: watchOS 8.3
Apple Security Update: About the security content of watchOS 8.3
Product: watchOS
Version: 8.3
CVE: CVE-2021-30995
Component: Preferences
Impact: A malicious application may be able to elevate privileges
Description: A race condition was addressed with improved state handling.
Apple
CVE-2021-30995: macOS Monterey 12.1
vendor_apple·2021-12-13·CVSS 7.0
CVE-2021-30995 [HIGH] CVE-2021-30995: macOS Monterey 12.1
Apple Security Update: About the security content of macOS Monterey 12.1
Product: macOS Monterey
Version: 12.1
CVE: CVE-2021-30995
Component: Preferences
Impact: A malicious application may be able to elevate privileges
Description: A race condition was addressed with improved state handling.
Apple
CVE-2021-30995: tvOS 15.2
vendor_apple·2021-12-13·CVSS 7.0
CVE-2021-30995 [HIGH] CVE-2021-30995: tvOS 15.2
Apple Security Update: About the security content of tvOS 15.2
Product: tvOS
Version: 15.2
CVE: CVE-2021-30995
Component: Preferences
Impact: A malicious application may be able to elevate privileges
Description: A race condition was addressed with improved state handling.
Apple
CVE-2021-30995: macOS Big Sur 11.6.2
vendor_apple·2021-12-13·CVSS 7.0
CVE-2021-30995 [HIGH] CVE-2021-30995: macOS Big Sur 11.6.2
Apple Security Update: About the security content of macOS Big Sur 11.6.2
Product: macOS Big Sur
Version: 11.6.2
CVE: CVE-2021-30995
Component: Preferences
Impact: A malicious application may be able to elevate privileges
Description: A race condition was addressed with improved state handling.
No detection rules found.
No public exploits indexed.
Trendmicro
This Week in Security News - January 21, 2022
blogs_trendmicro·2022-01-21
This Week in Security News - January 21, 2022
Cyber Crime
# This Week in Security News - January 21, 2022
This week, read about various cybersecurity threats that affect industrial control and the Cybersecurity and Infrastructure Security Agency (CISA)’s latest cyberattack warnings.
By: Jon Clay
Jan 21, 2022
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, read about various cybersecurity threats that affect industrial control. Also, read about the Cybersecurity and Infrastructure Security Agency (CISA)’s latest cyberattack warnings.
Read on:
Cybersecurity for Industrial Control Systems: Part 1
In this two-part series, Trend Micro looks at cybersecurity threats that affected industrial cont
Trendmicro
This Week in Security News - January 21, 2022
blogs_trendmicro·2022-01-21
This Week in Security News - January 21, 2022
Cyber Crime
# This Week in Security News - January 21, 2022
This week, read about various cybersecurity threats that affect industrial control and the Cybersecurity and Infrastructure Security Agency (CISA)’s latest cyberattack warnings.
By: Jon Clay
2022/01/21
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, read about various cybersecurity threats that affect industrial control. Also, read about the Cybersecurity and Infrastructure Security Agency (CISA)’s latest cyberattack warnings.
Read on:
Cybersecurity for Industrial Control Systems: Part 1
In this two-part series, Trend Micro looks at cybersecurity threats that affected industrial contro
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits & Vulnerabilities
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin Jan 14, 2022 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits & Vulnerabilities
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin 2022/01/14 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in ea
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Sfruttamento vulnerabilità
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin Jan 14, 2022 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits y vulnerabilidades
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin Jan 14, 2022 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits & Vulnerabilities
# Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin
2022/01/14
Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740, which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in ear
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Ausnutzung von Schwachstellen
## Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin Jan 14, 2022 Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740 , which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However,
Trendmicro
Analyzing an Old Bug and Discovering CVE-2021-30995
blogs_trendmicro·2022-01-14·CVSS 5.5
CVE-2021-30995 [MEDIUM] Analyzing an Old Bug and Discovering CVE-2021-30995
Exploits & Vulnerabilities
# Analyzing an Old Bug and Discovering CVE-2021-30995
A vulnerability found in 2021 has been patched and re-patched in the months since it was reported. We analyze the bug and outline the process that led to the discovery of CVE-2021-30995.
By: Mickey Jin
Jan 14, 2022
Read time: ( words)
Save to Folio
On April 26, 2021 Apple patched CVE-2021-1740, which was a vulnerable function inside the system daemon process cfprefsd (these types of processes usually run in the background and handle system tasks). The bug could have been exploited to read arbitrary files, write arbitrary files, and get root privilege escalation. It was addressed in Apple’s Security Update 2021-002 (Catalina) for a variety of Apple operating systems, including iOS and macOS. However, in e
https://support.apple.com/en-us/HT212975https://support.apple.com/en-us/HT212976https://support.apple.com/en-us/HT212978https://support.apple.com/en-us/HT212979https://support.apple.com/en-us/HT212980https://support.apple.com/en-us/HT212981https://www.zerodayinitiative.com/advisories/ZDI-22-360/https://support.apple.com/en-us/HT212975https://support.apple.com/en-us/HT212976https://support.apple.com/en-us/HT212978https://support.apple.com/en-us/HT212979https://support.apple.com/en-us/HT212980https://support.apple.com/en-us/HT212981https://www.zerodayinitiative.com/advisories/ZDI-22-360/
2021-08-24
Published