QID 376368

Date Published: 2022-02-02

QID 376368: Apple MacOS Monterey 12.2 Not Installed (HT213054)

macOS Monterey (version 12) is the 18th and current major release of macOS, Apple's desktop operating system for Macintosh computers.

CVE-2022-22586: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2022-22584: A memory corruption issue was addressed with improved validation.
CVE-2022-22578: A logic issue was addressed with improved validation.
CVE-2022-22585: An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization.
CVE-2022-22591: A memory corruption issue was addressed with improved memory handling.
CVE-2022-22587: A memory corruption issue was addressed with improved input validation.
CVE-2022-22593: A buffer overflow issue was addressed with improved memory handling.
CVE-2022-22579: An information disclosure issue was addressed with improved state management.
CVE-2022-22583: A permissions issue was addressed with improved validation.
CVE-2022-22589: A validation issue was addressed with improved input sanitization.
CVE-2022-22590: A use after free issue was addressed with improved memory management.
CVE-2022-22592: A logic issue was addressed with improved state management.
CVE-2022-22594:A cross-origin issue in the IndexDB API was addressed with improved input validation.

Affected Versions:
Apple MacOS Monterey version before 12.2

QID Detection Logic:
This QID checks for vulnerable versions of Monterey using sw_vers.

A malicious application may be able to execute arbitrary code with kernel privileges

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    The updates can be downloaded from Apple Downloads.

    For more information regarding the update can be found at HT213054.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213054 URL Logo support.apple.com/en-us/HT213054