CVE Vulnerabilities

CVE-2017-2429

Published: Apr 02, 2017 | Modified: Aug 24, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the FinderKit component. It allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging unexpected permission changes during an iCloud Sharing Send Link action.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple * 10.12.3 (including)

References