QID 376488

Date Published: 2022-03-29

QID 376488: Apple iTunes for Windows Prior to 12.12.3 Multiple Vulnerabilities (HT213188)

iTunes is a digital media player application for Mac OS and Windows developed by Apple.

iTunes is affected with multiple vulnerabilities.

CVE-2022-22611
CVE-2022-22612
CVE-2022-22662
CVE-2022-22629
Affected Versions:
Apple iTunes prior to 12.12.3 for Windows 10 and later

QID Detection Logic: (Authenticated)
It checks for vulnerable versions of Apple iTunes.

Successful exploitation of these vulnerabilities can be Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Apple iTunes 12.11.4 has been released to address these issue. The update can be downloaded and installed via Apple Downloads.

    Refer to Apple Security Updates for more information on the vulnerabilities and patching your system: HT213188

    Vendor References

    CVEs related to QID 376488

    Software Advisories
    Advisory ID Software Component Link
    HT213188 URL Logo support.apple.com/en-in/HT213188