cbcvebase.
CVE-2022-26773
published 2022-05-26

CVE-2022-26773: A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete files for…

PriorityP426high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
EPSS
0.55%
42.5th percentile
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete files for which it does not have permission.

Affected

3 ranges
VendorProductVersion rangeFixed in
appleitunes< 12.12.412.12.4
appleitunes_12.12.4_for_windows
appleitunes_for_windows>= unspecified < 12.1212.12

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.