CVE-2023-41989Apple Macos vulnerability

5 documents3 sources
Severity
6.8MEDIUMNVD
EPSS
0.1%
top 70.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateDec 11

Description

The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1. An attacker may be able to execute arbitrary code as root from the Lock Screen.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages5 packages

Appleapple/macos_sonoma14.1
CVEListV5apple/macosunspecified14.1
NVDapple/macos14.014.1
Appleapple/macos_ventura13.6.3
Appleapple/macos_monterey12.7.2

🔴Vulnerability Details

1
GHSA
GHSA-hhcv-5r95-mwmc: The issue was addressed by restricting options offered on a locked device2023-10-25

📋Vendor Advisories

3
Apple
CVE-2023-41989: macOS Monterey 12.7.22023-12-11
Apple
CVE-2023-41989: macOS Ventura 13.6.32023-12-11
Apple
CVE-2023-41989: macOS Sonoma 14.12023-10-25