CVE Vulnerabilities

CVE-2017-13786

Published: Nov 13, 2017 | Modified: Oct 03, 2019
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the APFS component. It does not properly restrict the DMA mapping time of FileVault decryption buffers, which allows attackers to read cleartext APFS data via a crafted Thunderbolt adapter.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple * 10.13.0 (including)

References