CISA KEV 정보
| 취약점명 | Apple Multiple Products Use-After-Free Vulnerability |
|---|---|
| 설명 | Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges. |
| 조치사항 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-416 |
| 등록일 (KEV) | 2025-01-29 |
| 조치 기한 | 2025-02-19 |
| 추가 참고 | https://support.apple.com/en-us/122066 ; https://support.apple.com/en-us/122068 ; https://support.apple.com/en-us/122071 ; https://support.apple.com/en-us/122072 ; https://support.apple.com/en-us/122073 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24085 |
NVD 상세 정보
CVSS v3.1: 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H설명: A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.
CWE: CWE-416 | CWE-416
참조
- https://support.apple.com/en-us/122066 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/122068 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/122071 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/122072 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/122073 [Release Notes, Vendor Advisory]
- http://seclists.org/fulldisclosure/2025/Apr/10 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Apr/5 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Apr/9 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jan/12 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jan/13 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jan/15 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jan/19 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jun/19 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Oct/1 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Oct/23 [Mailing List, Third Party Advisory]
- ... 외 5건
This product uses the NVD API but is not endorsed or certified by the NVD.