CVE-2022-26704
Summary
| CVE | CVE-2022-26704 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-26 19:15:00 UTC |
| Updated | 2022-11-10 16:29:00 UTC |
| Description | A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.4. An app may be able to gain elevated privileges. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Apple |
Macos |
All |
All |
All |
All |
| Operating System |
Apple |
Mac Os X |
All |
All |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
- |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2020 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2020-001 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2020-005 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2020-007 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2021-001 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2021-002 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2021-003 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2021-004 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2021-005 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2021-006 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2021-007 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2021-008 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2022-001 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2022-002 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2022-003 |
All |
All |
| Operating System |
Apple |
Mac Os X |
10.15.7 |
security_update_2022-004 |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Full Disclosure: APPLE-SA-2022-07-20-3 macOS Big Sur 11.6.8 |
FULLDISC |
seclists.org |
|
| Vulnerability-Disclosures/MNDT-2022-0032.md at master · mandiant/Vulnerability-Disclosures · GitHub |
MISC |
github.com |
|
| About the security content of Security Update 2022-005 Catalina - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of macOS Big Sur 11.6.8 - Apple Support |
CONFIRM |
support.apple.com |
|
| Full Disclosure: APPLE-SA-2022-07-20-4 Security Update 2022-005 Catalina |
FULLDISC |
seclists.org |
|
| About the security content of macOS Monterey 12.4 - Apple Support |
MISC |
support.apple.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376612 Apple macOS Monterey 12.4 Not Installed (HT213257)
- 376739 Apple macOS Security Update 2022-005 Catalina (HT213343)
- 376741 Apple macOS Big Sur 11.6.8 Not Installed (HT213344)