CVE-2022-26773

HIGH

iTunes < 12.12.4 - Unauthorized File Deletion via Logic Issue

Title source: llm
STIX 2.1

Description

A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete files for which it does not have permission.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213259

Scores

CVSS v3 7.1
EPSS 0.0054
EPSS Percentile 41.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (1)
apple/itunes < 12.12.4
Published May 26, 2022
Tracked Since Feb 18, 2026