CVE-2019-8801

HIGH

iTunes < 12.10.2 - Untrusted Search Path in Dynamic Library Loading

Title source: llm
STIX 2.1

Description

A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210722
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210726

Scores

CVSS v3 7.8
EPSS 0.0039
EPSS Percentile 30.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (2)
apple/itunes < 12.10.2
apple/mac_os_x < 10.15.1
Published Dec 18, 2019
Tracked Since Feb 18, 2026