cbcvebase.
CVE-2022-22657
published 2022-03-18

CVE-2022-22657: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3…

PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.05%
60.5th percentile
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

Affected

9 ranges
VendorProductVersion rangeFixed in
applegarageband< 10.4.610.4.6
applegarageband
applelogic_pro
applelogic_pro_x< 10.7.310.7.3
applemacos< 12.312.3
applemacos>= unspecified < 12.312.3
applemacos>= unspecified < 10.710.7
applemacos>= unspecified < 10.410.4
applemacos_monterey

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.