QID 376654

Date Published: 2022-06-07

QID 376654: Apple iTunes for Windows Prior to 12.12.4 Vulnerabilities (HT213259)

CVE-2022-26751 - A memory corruption issue was addressed with improved input validation.
CVE-2022-26711 - An integer overflow issue was addressed with improved input validation.
CVE-2022-26774 - A logic issue was addressed with improved state management.
CVE-2022-26773 - A logic issue was addressed with improved state management.
CVE-2022-26717 - A use after free issue was addressed with improved memory management.

Processing a maliciously crafted image may lead to arbitrary code execution.
A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
A local attacker may be able to elevate their privileges.
An application may be able to delete files for which it does not have permission.
Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Apple iTunes 12.12.4 has been released to address these security issues. For more information please refer to HT213259
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213259 URL Logo support.apple.com/en-us/HT213259