QID 375991

Date Published: 2021-10-27

QID 375991: Apple macOS Security Update 2021-007 Catalina (HT212871)

Apple has released this Security Update for multiple vulnerabilities

Affected versions:
Prior to Apple macOS Security Update 2021-007 Catalina.

QID Detection Logic (Authenticated):
This QID looks for the missing security patches from Catalina

Here are the list of consequences:

AppleScript: Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
Audio: A malicious application may be able to elevate privileges.
Bluetooth: A malicious application may be able to execute arbitrary code with kernel privileges.
ColorSync: Processing a maliciously crafted image may lead to arbitrary code execution.
CoreAudio: Processing a malicious audio file may result in unexpected application termination or arbitrary code execution.
CoreAudio: Processing a maliciously crafted file may disclose user information.
CoreGraphics: Processing a maliciously crafted PDF may lead to arbitrary code execution.
FileProvider: Unpacking a maliciously crafted archive may lead to arbitrary code execution.
Intel Graphics Driver: A malicious application may be able to execute arbitrary code with kernel privileges.
IOGraphics: A malicious application may be able to execute arbitrary code with kernel privileges.
Kernel: An application may be able to execute arbitrary code with kernel privileges.
Model I/O: Processing a maliciously crafted file may disclose user information.
SoftwareUpdate: A malicious application may gain access to a user's Keychain items.
UIKit: A person with physical access to an iOS device may be able to determine characteristics of a user's password in a secure text entry field.
zsh: A malicious application may be able to modify protected parts of the file system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    The vendor has released these fixes: Security Update 2021-007 Catalina.

    More information regarding the update can be found at HT212871.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212871 URL Logo support.apple.com/en-us/HT212871