CVE-2022-22639
published 2022-03-18CVE-2022-22639: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to…
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
8.07%
94.1th percentile
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.4_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 15.4 | 15.4 |
| apple | ipados | < 15.4 | 15.4 |
| apple | iphone_os | < 15.4 | 15.4 |
| apple | macos | < 12.3 | 12.3 |
| apple | macos | >= unspecified < 12.3 | 12.3 |
| apple | macos_monterey | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-22639: iOS 15.4 and iPadOS 15.4
vendor_apple·2022-03-14·CVSS 7.8
CVE-2022-22639 [HIGH] CVE-2022-22639: iOS 15.4 and iPadOS 15.4
Apple Security Update: About the security content of iOS 15.4 and iPadOS 15.4
Product: iOS 15.4 and iPadOS
Version: 15.4
CVE: CVE-2022-22639
Component: SoftwareUpdate
Impact: An application may be able to gain elevated privileges
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-22639: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 7.8
CVE-2022-22639 [HIGH] CVE-2022-22639: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2022-22639
Component: SoftwareUpdate
Impact: An application may be able to gain elevated privileges
Description: A logic issue was addressed with improved state management.
GHSA
GHSA-v9xh-2q6g-39c5: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-03-19
CVE-2022-22639 [HIGH] CWE-269 GHSA-v9xh-2q6g-39c5: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.
No detection rules found.
No public exploits indexed.
Trendmicro
Attack Surface Management 2022 Midyear Review Part 2
blogs_trendmicro·2022-10-27
Attack Surface Management 2022 Midyear Review Part 2
Privacy & Risks
# Attack Surface Management 2022 Midyear Review Part 2
In our 2022 midyear roundup, we examine the most significant trends and incidents that influenced the cybersecurity landscape in the first half of the year.
By: Trend Micro
2022/10/27
Read time: ( words)
Save to Folio
The cybersecurity landscape changed significantly in the first half of 2022. In our midyear roundup, we examine these changes and their effects on business operations as well as what you need to know about staying protected from online attacks.
In part one of the series, we talked about the growing attack surface and how actors have become more sophisticated. In this second instalment, we put ransomware and cloud environments into the spotlight. We also discuss other notable vulnerabilities that hav
Trendmicro
MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639
blogs_trendmicro·2022-04-04·CVSS 7.8
CVE-2022-22639 [HIGH] MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639
## MacOS SUHelper Root Privilege Escalation Vulnerability: A Deep Dive Into CVE-2022-22639
We discovered a now-patched vulnerability in macOS SUHelper, designated as CVE-2022-22639. If exploited, the vulnerability could allow malicious actors to gain root privilege escalation.
By: Mickey Jin Apr 04, 2022 Read time: ( words)
Save to Folio
We discovered a vulnerability in suhelperd, a helper daemon process for Software Update in macOS. A class inside suhelperd, SUHelper, provides an essential system service through the inter-process communication (IPC) mechanism. The process runs as root and is signed with special entitlements, such as com.apple.rootless.install, which grants the process permission to bypass System Integrity Protection (SIP) restrictions. This combination of functionalit
Trendmicro
MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639
blogs_trendmicro·2022-04-04·CVSS 7.8
CVE-2022-22639 [HIGH] MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639
# MacOS SUHelper Root Privilege Escalation Vulnerability: A Deep Dive Into CVE-2022-22639
We discovered a now-patched vulnerability in macOS SUHelper, designated as CVE-2022-22639. If exploited, the vulnerability could allow malicious actors to gain root privilege escalation.
By: Mickey Jin
Apr 04, 2022
Read time: ( words)
Save to Folio
We discovered a vulnerability in suhelperd, a helper daemon process for Software Update in macOS. A class inside suhelperd, SUHelper, provides an essential system service through the inter-process communication (IPC) mechanism. The process runs as root and is signed with special entitlements, such as com.apple.rootless.install, which grants the process permission to bypass System Integrity Protection (SIP) restrictions. This combination of functionalit
Trendmicro
MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639
blogs_trendmicro·2022-04-04·CVSS 7.8
CVE-2022-22639 [HIGH] MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639
## MacOS SUHelper Root Privilege Escalation Vulnerability: A Deep Dive Into CVE-2022-22639
We discovered a now-patched vulnerability in macOS SUHelper, designated as CVE-2022-22639. If exploited, the vulnerability could allow malicious actors to gain root privilege escalation.
By: Mickey Jin 2022/04/04 Read time: ( words)
Save to Folio
We discovered a vulnerability in suhelperd, a helper daemon process for Software Update in macOS. A class inside suhelperd, SUHelper, provides an essential system service through the inter-process communication (IPC) mechanism. The process runs as root and is signed with special entitlements, such as com.apple.rootless.install, which grants the process permission to bypass System Integrity Protection (SIP) restrictions. This combination of functionalitie
Trendmicro
MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639
blogs_trendmicro·2022-04-04·CVSS 7.8
CVE-2022-22639 [HIGH] MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639
# MacOS SUHelper Root Privilege Escalation Vulnerability: A Deep Dive Into CVE-2022-22639
We discovered a now-patched vulnerability in macOS SUHelper, designated as CVE-2022-22639. If exploited, the vulnerability could allow malicious actors to gain root privilege escalation.
By: Mickey Jin
2022/04/04
Read time: ( words)
Save to Folio
We discovered a vulnerability in suhelperd, a helper daemon process for Software Update in macOS. A class inside suhelperd, SUHelper, provides an essential system service through the inter-process communication (IPC) mechanism. The process runs as root and is signed with special entitlements, such as com.apple.rootless.install, which grants the process permission to bypass System Integrity Protection (SIP) restrictions. This combination of functionalitie
2022-03-18
Published