Record summary

CVE-2021-30860 has a selected CVSS score of 7.8 (high); EIP currently links 3 repository PoCs. CISA lists CVE-2021-30860 in KEV.

Description

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Sep 7, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
3

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListBefore 14.8affected
CVE ListBefore 11.6affected
Before 2021-005affected
CVE ListBefore 7.6affected

Proofs of concept

3

Repository PoCs

GitHubLevilutz/CVE-2021-30860Repository PoCby LevilutzStars: 11Not analyzed7 files

15.6 KiB

GitHub

PoC details
GitHub30440r/gexRepository PoCby 30440rStars: 5Not analyzed12 files

77.6 KiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubjeffssh/CVE-2021-30860Repository PoCby jeffsshStars: 100Not analyzed32 files

2.4 MiB

GitHub

PoC details

References

Showing 12 of 16