QID 376181

Date Published: 2021-12-16

QID 376181: Apple macOS Security Update 2021-008 Catalina (HT212981)

Apple has released this Security Update for multiple vulnerabilities

Affected versions:
Prior to Apple macOS Security Update 2021-008 Catalina.

QID Detection Logic (Authenticated):
This QID looks for the missing security patches from Catalina

Here is the list of consequences:

Archive Utility: A malicious application may bypass Gatekeeper checks.
Bluetooth: A malicious application may be able to disclose kernel memory
ColorSync: Processing a maliciously crafted image may lead to arbitrary code execution
CoreAudio: Playing a malicious audio file may lead to arbitrary code execution and Parsing a maliciously crafted audio file may lead to the disclosure of user information
Crash Reporter: A local attacker may be able to elevate their privileges
Graphics Drivers: A malicious application may be able to execute arbitrary code with kernel privileges
Help Viewer: Processing a maliciously crafted URL may cause unexpected JavaScript execution from a file on disk
ImageIO: Processing a maliciously crafted image may lead to arbitrary code execution
Intel Graphics Driver: An application may be able to execute arbitrary code with kernel privileges
IOUSBHostFamily: A remote attacker may be able to cause unexpected application termination or heap corruption
Kernel: An application may be able to execute arbitrary code with kernel privileges
LaunchServices: A malicious application may bypass Gatekeeper checks
Model I/O: Processing a maliciously crafted USD file may disclose memory contents
Preferences: A malicious application may be able to elevate privileges
Sandbox: A malicious application may be able to bypass certain Privacy preferences
Script Editor: A malicious OSAX scripting addition may bypass Gatekeeper checks and circumvent sandbox restrictions
TCC: A local user may be able to modify protected parts of the file system
Wi-Fi: A local user may be able to cause unexpected system termination or read kernel memory

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    The vendor has released these fixes: Security Update 2021-008 Catalina.

    More information regarding the update can be found at HT212981.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212981 URL Logo support.apple.com/en-us/HT212981