CVE-2019-8814
Published on: 12/18/2019 12:00:00 AM UTC
Last Modified on: 05/18/2021 01:12:00 PM UTC
Certain versions of Icloud from Apple contain the following vulnerability:
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVE-2019-8814 has been assigned by
product-sec[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 9.3 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
About the security content of iCloud for Windows 10.8 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
About the security content of iCloud for Windows 7.15 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
About the security content of iOS 13.2 and iPadOS 13.2 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
WebkitGTK+: Multiple vulnerabilities (GLSA 202003-22) — Gentoo security | security.gentoo.org text/html |
![]() |
About the security content of tvOS 13.2 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
About the security content of Safari 13.0.3 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
About the security content of iTunes 12.10.2 for Windows - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
Related QID Numbers
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 377553 Alibaba Cloud Linux Security Update for webkitgtk4 (ALINUX2-SA-2020:0147)
- 501288 Alpine Linux Security Update for webkit2gtk
- 770068 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:0436)
- 940362 AlmaLinux Security Update for GNOME (ALSA-2020:4451)
- 960761 Rocky Linux Security Update for GNOME (RLSA-2020:4451)
Exploit/POC from Github
PoC for exploiting CVE-2019-8814
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apple | Icloud | All | All | All | All |
Application | Apple | Icloud | All | All | All | All |
Application | Apple | Icloud | All | All | All | All |
Operating System | Apple | Ipados | All | All | All | All |
Operating System | Apple | Ipados | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Application | Apple | Itunes | All | All | All | All |
Application | Apple | Itunes | All | All | All | All |
Application | Apple | Safari | All | All | All | All |
Application | Apple | Safari | All | All | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Redhat | Enterprise Linux Desktop | 7.0 | All | All | All |
Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
Operating System | Redhat | Enterprise Linux Workstation | 7.0 | All | All | All |
- cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*:
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|