CVE-2017-2474
Description
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. An off-by-one error allows attackers to execute arbitrary code in a privileged context via a crafted app.
In plain language
AI Worth attentionThis is a serious Apple iPhone/iPad/Mac/TV/watch security bug that can allow an app to take over the device’s most powerful features; if you’re running an older iOS/macOS/tvOS/watchOS version, you should update.
CVE-2017-2474 is a kernel “off-by-one” bug in certain Apple operating systems that allows attackers to execute arbitrary code in a privileged context by using a crafted app; at least one public exploit is available and interest is rising, so you should update your devices.
What to do now
- Check each affected device’s current iOS/macOS/tvOS/watchOS version.
- For iOS: update to iOS 10.3 or newer (older than 10.3 is affected).
- For macOS: update to macOS 10.12.4 or newer (older than 10.12.4 is affected).
- For tvOS: update to tvOS 10.2 or newer (older than 10.2 is affected).
- For watchOS: update to watchOS 3.2 or newer (older than 3.2 is affected).
- Follow Apple’s guidance in the remediation articles linked in the notice, and then re-check that your devices show the updated versions.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-2474 and every CVE in our database. Create a free account — no credit card required.
Create Free Account