CVE-2017-13880

HIGH

iPhone OS < 11.2 and watchOS < 4.2 - Remote Code Execution via Memory Corruption

Title source: llm
STIX 2.1

Description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An application may be able to execute arbitrary code with kernel privilege.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT208325
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT208334

Scores

CVSS v3 7.8
EPSS 0.0089
EPSS Percentile 55.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
apple/iphone_os < 11.2
apple/watchos < 4.2
Published Dec 23, 2021
Tracked Since Feb 18, 2026