QID 375801
Date Published: 2021-08-17
QID 375801: Apple iTunes for Windows Prior to 12.11.4 Multiple Vulnerabilities (HT212609)
iTunes is a digital media player application for Mac OS and Windows developed by Apple.
iTunes is affected with multiple vulnerabilities.
CVE-2021-30779: Processing a maliciously crafted image may lead to arbitrary code execution.
CVE-2021-30785: A buffer overflow was addressed with improved bounds checking.
Affected Versions:
Apple iTunes prior to 12.11.4 for Windows 10 and later
QID Detection Logic: (Authenticated)
It checks for vulnerable versions of Apple iTunes.
Successful exploitation of these vulnerabilities can lead to arbitrary code execution and a buffer overflow vulnerability.
Solution
Apple iTunes 12.11.4 has been released to address these issue. The update can be downloaded and installed via Apple Downloads.
Refer to Apple Security Updates for more information on the vulnerabilities and patching your system: HT212609
Vendor References
- HT212609 -
support.apple.com/en-us/HT212609
CVEs related to QID 375801
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| HT212609 | WIndows |
|