CVE-2022-32844
published 2023-02-27CVE-2022-32844: A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app with arbitrary…
PriorityP433medium6.3CVSS 3.1
AVLACHPRLUINSUCHIHAN
EPSS
0.20%
9.6th percentile
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.6_and_ipados | — | — |
| apple | ipados | < 15.6 | 15.6 |
| apple | iphone_os | < 15.6 | 15.6 |
| apple | tvos | < 15.6 | 15.6 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 15.6 | 15.6 |
| apple | watchos | < 8.7 | 8.7 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.7 | 8.7 |
| apple | watchos | >= unspecified < 15.6 | 15.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5p5j-vwv3-3hm9: A race condition was addressed with improved state handling
ghsa_unreviewed·2023-02-27
CVE-2022-32844 [MEDIUM] CWE-362 GHSA-5p5j-vwv3-3hm9: A race condition was addressed with improved state handling
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication.
Ivanti
Ivanti Security Advisory: CVE-2024-32844
vendor_ivanti·2024-11-13·CVSS 7.2
CVE-2024-32844 [HIGH] CWE-89 Ivanti Security Advisory: CVE-2024-32844
Ivanti Security Advisory: CVE-2024-32844
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE IDs: CVE-2024-32844
CVSS Base Score: 7.2
Severity: HIGH
CWEs: CWE-89
Apple
CVE-2022-32844: watchOS 8.7
vendor_apple·2022-07-20·CVSS 6.3
CVE-2022-32844 [MEDIUM] CVE-2022-32844: watchOS 8.7
Apple Security Update: About the security content of watchOS 8.7
Product: watchOS
Version: 8.7
CVE: CVE-2022-32844
Component: Kernel
Impact: An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-32844: tvOS 15.6
vendor_apple·2022-07-20·CVSS 6.3
CVE-2022-32844 [MEDIUM] CVE-2022-32844: tvOS 15.6
Apple Security Update: About the security content of tvOS 15.6
Product: tvOS
Version: 15.6
CVE: CVE-2022-32844
Component: Kernel
Impact: An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-32844: iOS 15.6 and iPadOS 15.6
vendor_apple·2022-07-20·CVSS 6.3
CVE-2022-32844 [MEDIUM] CVE-2022-32844: iOS 15.6 and iPadOS 15.6
Apple Security Update: About the security content of iOS 15.6 and iPadOS 15.6
Product: iOS 15.6 and iPadOS
Version: 15.6
CVE: CVE-2022-32844
Component: Kernel
Impact: An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication
Description: A logic issue was addressed with improved state management.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-27
Published