CERT-In Vulnerability Note
CIVN-2024-0159
Remote Code Execution Vulnerability in Apple iTunes
Original Issue Date:May 10, 2024
Severity Rating: HIGH
Software Affected
- Apple iTunes versions prior to 12.13.2 for Windows
Overview
A vulnerability has been reported in Apple iTunes which could be exploited by a remote attacker to execute arbitrary code on the targeted system.
Description
This vulnerability exists in Apple Product due to improper checks in CoreMedia component. A remote attacker could exploit this vulnerability by sending a specially crafted request.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned in Apple Security updates:
https://support.apple.com/en-au/HT214099
Vendor Information
Apple
https://support.apple.com/en-au/HT214099
References
https://support.apple.com/en-au/HT214099
CVE Name
CVE-2024-27793
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|