CVE-2015-1062

Apple iOS <8.2 & Apple TV <7.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app.

References (5)

Core 5
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Mar/msg00001.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT204426
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Mar/msg00000.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031864
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT204423

Scores

EPSS 0.0147
EPSS Percentile 71.1%

Details

CWE
CWE-19
Status published
Products (2)
apple/iphone_os < 8.1.3
apple/tvos < 7.0.3
Published Mar 12, 2015
Tracked Since Feb 18, 2026