HIGH

CVE-2020-27930

Apple Ipados 2020-12-08 CVSS v3.1
CVSS
7.8
KEV

Description

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.

Summary dbcve.org

A memory corruption vulnerability in Apple's font processing subsystem allows arbitrary code execution when a user processes a maliciously crafted font file. The vulnerability was addressed through improved input validation in the affected operating systems.

Mitigation

Apply the available security updates for affected Apple products (iOS 12.4.9+, iOS 14.2+, iPadOS 14.2+, watchOS 5.3.9+, watchOS 6.2.9+, watchOS 7.1+, macOS High Sierra 2020-006+, macOS Mojave 2020-006+, macOS Catalina 10.15.7+, macOS Big Sur 11.0.1+) to address the vulnerability.

Proof of Concept

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

22.01%
Probability of exploitation in next 30 days
97.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE