CVE-2020-3846
HIGHiCloud < 7.17 - Buffer Overflow via Malicious XML Processing
Title source: llmDescription
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.
References (2)
Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT210947
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT210948
Scores
CVSS v3
8.8
EPSS
0.0178
EPSS Percentile
75.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-20
Status
published
Products (7)
apple/icloud
< 7.17
apple/ipados
< 13.3.1
apple/iphone_os
< 13.3.1
apple/itunes
< 12.10.4
apple/mac_os_x
< 10.15.3
apple/tvos
< 13.3.1
apple/watchos
< 6.1.2
Published
Feb 27, 2020
Tracked Since
Feb 18, 2026