QID 376650

Date Published: 2022-06-08

QID 376650: Apple iTunes for Windows Prior to 12.11.3 Vulnerabilities (HT212319)

CVE-2021-1857 - A memory initialization issue was addressed with improved memory handling.
CVE-2021-1811 - A logic issue was addressed with improved state management.
CVE-2021-1825 - An input validation issue was addressed with improved input validation.
CVE-2020-7463 - A use after free issue was addressed with improved memory management.

Processing maliciously crafted web content may disclose sensitive user information.
Processing a maliciously crafted font may result in the disclosure of process memory.
Processing maliciously crafted web content may lead to a cross site scripting attack.
A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Apple iTunes 12.11.3 has been released to address these security issues. For more information please refer to HT212319
    Vendor References

    CVEs related to QID 376650

    Software Advisories
    Advisory ID Software Component Link
    HT212319 URL Logo support.apple.com/en-us/HT212319