packetstormsecurity.com
http://packetstormsecurity.com/files/161294/Apple-Safari-Remote-Code-Execution.html CVE-2020-27930
HIGHCISA KEV
Apple Multiple Products Memory Corruption Vulnerability
Record summary
CVE-2020-27930 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2020-27930 in KEV.
Description
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Oct 26, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse Apple / Multiple Products | CISA | Version data not supplied | |
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 14.2 | affected |
macOSBrowse Apple / macOS | CVE List | Before 11.0 | affected |
| Before 12.4 | affected | ||
| Before 6.2 | affected | ||
| Before 5.3 | affected | ||
| Before 2020 | affected | ||
| Before 10.15 | affected | ||
watchOSBrowse Apple / watchOS | CVE List | Before 7.1 | affected |
Proofs of concept
1Repository PoCs
GitHubFunPhishing/Apple-Safari-Remote-Code-Execution-CVE-2020-27930Repository PoCby FunPhishingStars: 0Not analyzed2 files
References
1220201215 APPLE-SA-2020-12-14-4 Additional information for APPLE-SA-2020-11-13-1 macOS Big Sur 11.0.1mailing list
http://seclists.org/fulldisclosure/2020/Dec/32 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-27930 support.apple.com
https://support.apple.com/en-us/HT211928 support.apple.com
https://support.apple.com/en-us/HT211929 support.apple.com
https://support.apple.com/en-us/HT211931 support.apple.com
https://support.apple.com/en-us/HT211940 support.apple.com
https://support.apple.com/en-us/HT211944 support.apple.com
https://support.apple.com/en-us/HT211945 support.apple.com
https://support.apple.com/en-us/HT211946 support.apple.com
https://support.apple.com/en-us/HT211947 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-27930