CVE-2011-0227

EXPLOITED

iPhone OS < 4.2.9 and 4.3.x < 4.3.4 - Local Privilege Escalation via IOMobileFrameBuffer Queueing Primitives

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2011-0227 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The queueing primitives in IOMobileFrameBuffer in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 do not properly perform type conversion, which allows local users to gain privileges via a crafted application.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4803
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Jul/msg00000.html
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Jul/msg00001.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4802

Scores

EPSS 0.0032
EPSS Percentile 23.8%

Details

VulnCheck KEV 2012-10-09
CWE
CWE-264
Status published
Products (36)
apple/iphone_os 1.0.0
apple/iphone_os 1.0.1
apple/iphone_os 1.0.2
apple/iphone_os 1.1.0
apple/iphone_os 1.1.1
apple/iphone_os 1.1.2
apple/iphone_os 1.1.3
apple/iphone_os 1.1.4
apple/iphone_os 1.1.5
apple/iphone_os 2.0
... and 26 more
Published Jul 19, 2011
Tracked Since Feb 18, 2026