CVE-2023-23513Classic Buffer Overflow in Apple Macos

Severity
9.8CRITICALNVD
EPSS
1.0%
top 23.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateJul 13

Description

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Appleapple/macos_monterey12.6.3
CVEListV5apple/macosunspecified11.7+2
NVDapple/macos12.012.6.3+2
Appleapple/macos_big_sur11.7.3

🔴Vulnerability Details

1
GHSA
GHSA-2rvj-6xx4-893j: A buffer overflow issue was addressed with improved memory handling2023-02-27

📋Vendor Advisories

3
Apple
CVE-2023-23513: macOS Ventura 13.22023-01-23
Apple
CVE-2023-23513: macOS Big Sur 11.7.32023-01-23
Apple
CVE-2023-23513: macOS Monterey 12.6.32023-01-23

🕵️Threat Intelligence

2
Talos
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation2023-07-13
Talos
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation2023-07-13