Description
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
In plain language
AI Worth attentionCVE-2017-13867 is a flaw in Apple iOS/macOS/tvOS/watchOS that a malicious app can use (after you run it) to take over the device or crash it; if your device is on an older OS version, you should update.
CVE-2017-13867 is a local Kernel memory-corruption issue (CWE-119) in iOS/macOS/tvOS/watchOS that requires no authentication but does require user action to run a specially crafted malicious app; it can lead to arbitrary code execution with highest privileges or denial of service.
What to do now
- Check whether your Apple devices (iOS, macOS, tvOS, watchOS) are running versions older than 11.2, 10.13.2, 11.2, and 4.2 respectively.
- Update iPhone/iPad to iOS 11.2 or later.
- Update Mac to macOS 10.13.2 or later.
- Update Apple TV to tvOS 11.2 or later.
- Update Apple Watch to watchOS 4.2 or later.
- If you can’t update right away, avoid installing or running any untrusted app packages and remove any newly installed suspicious apps immediately.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-13867 and every CVE in our database. Create a free account — no credit card required.
Create Free Account