ID

VAR-201702-0220


CVE

CVE-2016-7621


TITLE

plural Apple Vulnerability in the kernel component of a product that allows arbitrary code execution in privileged contexts

Trust: 0.8

sources: JVNDB: JVNDB-2016-007438

DESCRIPTION

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via unspecified vectors. Apple macOS, watchOS, iOS, and tvOS are prone to multiple security vulnerabilities. Attackers can exploit these issues to execute arbitrary code, obtain sensitive information and bypass security restrictions. Failed exploit attempts may result in a denial-of-service condition. Versions prior to iOS 10.2, watchOS 3.1.1, macOS 10.12.2, and tvOS 10.1 are vulnerable. Apple iOS is an operating system developed for mobile devices; watchOS is an operating system for smart watches. CVE-2017-2363: lokihardt of Google Project Zero Installation note: Instructions on how to update your Apple Watch software are available at https://support.apple.com/kb/HT204641 To check the version on your Apple Watch, open the Apple Watch app on your iPhone and select "My Watch > General > About". Alternatively, on your watch, select "My Watch > General > About". -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 APPLE-SA-2016-12-13-6 Additional information for APPLE-SA-2016-12-12-3 tvOS 10.1 tvOS 10.1 addresses the following: Audio Available for: Apple TV (4th generation) Impact: Processing a maliciously crafted file may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved input validation. CVE-2016-7658: Haohao Kong of Keen Lab (@keen_lab) of Tencent CVE-2016-7659: Haohao Kong of Keen Lab (@keen_lab) of Tencent Entry added December 13, 2016 CoreFoundation Available for: Apple TV (4th generation) Impact: Processing malicious strings may lead to an unexpected application termination or arbitrary code execution Description: A memory corruption issue existed in the processing of strings. This issue was addressed through improved bounds checking. CVE-2016-7663: an anonymous researcher Entry added December 13, 2016 CoreGraphics Available for: Apple TV (4th generation) Impact: Processing a maliciously crafted font file may lead to unexpected application termination Description: A null pointer dereference was addressed through improved input validation. CVE-2016-7627: TRAPMINE Inc. & Meysam Firouzi @R00tkitSMM Entry added December 13, 2016 CoreMedia External Displays Available for: Apple TV (4th generation) Impact: A local application may be able to execute arbitrary code in the context of the mediaserver daemon Description: A type confusion issue was addressed through improved memory handling. CVE-2016-7655: Keen Lab working with Trend Micro's Zero Day Initiative Entry added December 13, 2016 CoreMedia Playback Available for: Apple TV (4th generation) Impact: Processing a maliciously crafted .mp4 file may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved memory handling. CVE-2016-7588: dragonltx of Huawei 2012 Laboratories Entry added December 13, 2016 CoreText Available for: Apple TV (4th generation) Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: Multiple memory corruption issues existed in the handling of font files. These issues were addressed through improved bounds checking. CVE-2016-7595: riusksk(ae3aY=) of Tencent Security Platform Department Entry added December 13, 2016 Disk Images Available for: Apple TV (4th generation) Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed through improved input validation. CVE-2016-7616: daybreaker@Minionz working with Trend Micro's Zero Day Initiative Entry added December 13, 2016 FontParser Available for: Apple TV (4th generation) Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: Multiple memory corruption issues existed in the handling of font files. These issues were addressed through improved bounds checking. CVE-2016-4691: riusksk(ae3aY=) of Tencent Security Platform Department Entry added December 13, 2016 FontParser Available for: Apple TV (4th generation) Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: A buffer overflow existed in the handling of font files. This issue was addressed through improved bounds checking. CVE-2016-4688: Simon Huang of Alipay company, thelongestusernameofall@gmail.com Entry added December 13, 2016 ICU Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved memory handling. CVE-2016-7594: AndrA(c) Bargull Entry added December 13, 2016 ImageIO Available for: Apple TV (4th generation) Impact: A remote attacker may be able to leak memory Description: An out-of-bounds read was addressed through improved bounds checking. CVE-2016-7591: daybreaker of Minionz Entry added December 13, 2016 IOKit Available for: Apple TV (4th generation) Impact: An application may be able to read kernel memory Description: A memory corruption issue was addressed through improved input validation. CVE-2016-7657: Keen Lab working with Trend Micro's Zero Day Initiative Entry added December 13, 2016 Kernel Available for: Apple TV (4th generation) Impact: An application may be able to execute arbitrary code with kernel privileges Description: Multiple memory corruption issues were addressed through improved input validation. CVE-2016-7606: @cocoahuke, Chen Qin of Topsec Alpha Team (topsec.com) CVE-2016-7612: Ian Beer of Google Project Zero Entry added December 13, 2016 Kernel Available for: Apple TV (4th generation) Impact: An application may be able to read kernel memory Description: An insufficient initialization issue was addressed by properly initializing memory returned to user space. CVE-2016-7621: Ian Beer of Google Project Zero Entry added December 13, 2016 Kernel Available for: Apple TV (4th generation) Impact: A local user may be able to gain root privileges Description: A memory corruption issue was addressed through improved input validation. CVE-2016-7637: Ian Beer of Google Project Zero Entry added December 13, 2016 libarchive Available for: Apple TV (4th generation) Impact: A local attacker may be able to overwrite existing files Description: A validation issue existed in the handling of symlinks. This issue was addressed through improved validation of symlinks. CVE-2016-7619: an anonymous researcher Entry added December 13, 2016 Power Management Available for: Apple TV (4th generation) Impact: A local user may be able to gain root privileges Description: An issue in mach port name references was addressed through improved validation. CVE-2016-7661: Ian Beer of Google Project Zero Entry added December 13, 2016 Profiles Available for: Apple TV (4th generation) Impact: Opening a maliciously crafted certificate may lead to arbitrary code execution Description: A memory corruption issue existed in the handling of certificate profiles. This issue was addressed through improved input validation. CVE-2016-7626: Maksymilian Arciemowicz (cxsecurity.com) Security Available for: Apple TV (4th generation) Impact: An attacker may be able to exploit weaknesses in the 3DES cryptographic algorithm Description: 3DES was removed as a default cipher. CVE-2016-4693: GaA<<tan Leurent and Karthikeyan Bhargavan from INRIA Paris Entry added December 13, 2016 Security Available for: Apple TV (4th generation) Impact: An attacker in a privileged network position may be able to cause a denial of service Description: A validation issue existed in the handling of OCSP responder URLs. This issue was addressed by verifying OCSP revocation status after CA validation and limiting the number of OCSP requests per certificate. CVE-2016-7636: Maksymilian Arciemowicz (cxsecurity.com) Entry added December 13, 2016 Security Available for: Apple TV (4th generation) Impact: Certificates may be unexpectedly evaluated as trusted Description: A certificate evaluation issue existed in certificate validation. This issue was addressed through additional validation of certificates. CVE-2016-7662: Apple Entry added December 13, 2016 syslog Available for: Apple TV (4th generation) Impact: A local user may be able to gain root privileges Description: An issue in mach port name references was addressed through improved validation. CVE-2016-7660: Ian Beer of Google Project Zero Entry added December 13, 2016 WebKit Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed through improved memory handling. CVE-2016-4692: Apple CVE-2016-7635: Apple CVE-2016-7652: Apple Entry added December 13, 2016 WebKit Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may result in the disclosure of process memory Description: A memory corruption issue was addressed through improved input validation. CVE-2016-4743: Alan Cutter Entry added December 13, 2016 WebKit Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may result in the disclosure of user information Description: A validation issue was addressed through improved state management. CVE-2016-7586: Boris Zbarsky Entry added December 13, 2016 WebKit Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed through improved state management. CVE-2016-7587: Adam Klein CVE-2016-7610: Zheng Huang of the Baidu Security Lab working with Trend Micro's Zero Day Initiative CVE-2016-7611: an anonymous researcher working with Trend Micro's Zero Day Initiative CVE-2016-7639: Tongbo Luo of Palo Alto Networks CVE-2016-7640: Kai Kang of Tencent's Xuanwu Lab (tencent.com) CVE-2016-7641: Kai Kang of Tencent's Xuanwu Lab (tencent.com) CVE-2016-7642: Tongbo Luo of Palo Alto Networks CVE-2016-7645: Kai Kang of Tencent's Xuanwu Lab (tencent.com) CVE-2016-7646: Kai Kang of Tencent's Xuanwu Lab (tencent.com) CVE-2016-7648: Kai Kang of Tencent's Xuanwu Lab (tencent.com) CVE-2016-7649: Kai Kang of Tencent's Xuanwu Lab (tencent.com) CVE-2016-7654: Keen Lab working with Trend Micro's Zero Day Initiative Entry added December 13, 2016 WebKit Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved state management. CVE-2016-7589: Apple CVE-2016-7656: Keen Lab working with Trend Micro's Zero Day Initiative Entry added December 13, 2016 WebKit Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may result in the disclosure of process memory Description: An uninitialized memory access issue was addressed through improved memory initialization. CVE-2016-7598: Samuel GroA Entry added December 13, 2016 WebKit Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may result in the disclosure of user information Description: An issue existed in the handling of HTTP redirects. This issue was addressed through improved cross origin validation. CVE-2016-7599: Muneaki Nishimura (nishimunea) of Recruit Technologies Co., Ltd. Entry added December 13, 2016 WebKit Available for: Apple TV (4th generation) Impact: Processing maliciously crafted web content may lead to an unexpected application termination or arbitrary code execution Description: A memory corruption issue was addressed through improved state management. CVE-2016-7632: Jeonghoon Shin Entry added December 13, 2016 Installation note: Apple TV will periodically check for software updates. Alternatively, you may manually check for software updates by selecting "Settings -> System -> Software Update -> Update Software." To check the current version of software, select "Settings -> General -> About." Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJYT7LKAAoJEIOj74w0bLRGRpYP/RiSCpisB2QI8kO5eyhqQQw8 Cc8c+l7wlpWoeUuNznXtGBRrMlL21Xzg6HZXkRepwh7SvwKmr2Xq6tw9VRrmT554 qTVcSe/8MZEb/NcsRvwS5vw70738WLDp8l1+3jsXm46LOpn9Xyolcl7uUS8Z+mxU yDe4lMWIrNIHqQmDfXWILCL/2szx/Dn324b7klcRUy4p6JLyHwQgegQm6O582miJ SFeknLzjqhuukGnaywhwoR8GDcsFtPT4ZFgum2kBB1Ke7Q6KmeenrSN0FVH5Z+zs 5/kXWBl0xHNZigrgHhO21hzGXX0SUq/SbLEBtuBzUJG3the5Zp24T8nOeNem5I5F GJZd+S7PBnXpH+y+kURk6dVuKGDHv8tnp909v6QXjw35+oMvjEfuD64oSYf8FJNt VTVU8R+hWYqexVQSkLjOPo6TxgrlHtHZ3Kw2tOwisuB3afSSVTS6p0y+EPxUNHXw kzF5nOiEBnuTsqTiuuvTC0+p/XvFcGhVYZwygzOWeh0jKUDWXrnqY4XcqmtCPSl4 QXCNSSH8tAaPh/VIZpBYFVTRSrFqhqz17cwxEnsw7QkhFV8L8haWNfRL062swkHV 65Uq1oNytpw5bT5tL3NmBumknb+Y6/KNGT1+PQVc9cccQJtDjcjItqwfnTl0NdkB wTrD0dsr90pjud+QyhXr =YVOV -----END PGP SIGNATURE-----

Trust: 2.25

sources: NVD: CVE-2016-7621 // JVNDB: JVNDB-2016-007438 // BID: 94905 // VULHUB: VHN-96441 // PACKETSTORM: 140688 // PACKETSTORM: 140156 // PACKETSTORM: 140157

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:eqversion:10.12.1

Trust: 1.4

vendor:applemodel:iphone osscope:lteversion:10.1.1

Trust: 1.0

vendor:applemodel:watchosscope:lteversion:2.2.2

Trust: 1.0

vendor:applemodel:mac os xscope:lteversion:10.12.1

Trust: 1.0

vendor:applemodel:watchosscope:eqversion:2.2.2

Trust: 0.9

vendor:applemodel:iosscope:ltversion:10.2 (ipad first 4 after generation )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:10.2 (iphone 5 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:10.2 (ipod touch first 6 after generation )

Trust: 0.8

vendor:applemodel:tvosscope:ltversion:10.1 (apple tv first 4 generation )

Trust: 0.8

vendor:applemodel:watchosscope:ltversion:3.1.3 (apple watch all models )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:10.1.1

Trust: 0.6

vendor:applemodel:watch osscope:eqversion:3.1.1

Trust: 0.6

vendor:applemodel:watchosscope:eqversion:10.1.1

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:3.1.1

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:2.2.1

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:2.0.1

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:1.0.1

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:3

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:2.2

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:2.0

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:1.0

Trust: 0.3

vendor:applemodel:watchscope:eqversion:0

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:10.0.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.2.2

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.2.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.1.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.2

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.1

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:9.0

Trust: 0.3

vendor:applemodel:tvosscope:eqversion:10

Trust: 0.3

vendor:applemodel:tvscope:eqversion:0

Trust: 0.3

vendor:applemodel:macosscope:eqversion:10.12.1

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:50

Trust: 0.3

vendor:applemodel:iosscope:eqversion:40

Trust: 0.3

vendor:applemodel:iosscope:eqversion:30

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:10

Trust: 0.3

vendor:applemodel:watchosscope:neversion:3.1.3

Trust: 0.3

vendor:applemodel:watchosscope:neversion:3.1.1

Trust: 0.3

vendor:applemodel:tvosscope:neversion:10.1

Trust: 0.3

vendor:applemodel:macosscope:neversion:10.12.2

Trust: 0.3

vendor:applemodel:iosscope:neversion:10.2

Trust: 0.3

sources: BID: 94905 // JVNDB: JVNDB-2016-007438 // CNNVD: CNNVD-201612-457 // NVD: CVE-2016-7621

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-7621
value: HIGH

Trust: 1.0

NVD: CVE-2016-7621
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201612-457
value: HIGH

Trust: 0.6

VULHUB: VHN-96441
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2016-7621
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-96441
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-7621
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-96441 // JVNDB: JVNDB-2016-007438 // CNNVD: CNNVD-201612-457 // NVD: CVE-2016-7621

PROBLEMTYPE DATA

problemtype:CWE-416

Trust: 1.9

sources: VULHUB: VHN-96441 // JVNDB: JVNDB-2016-007438 // NVD: CVE-2016-7621

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201612-457

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201612-457

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-007438

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-96441

PATCH

title:Apple security updatesurl:https://support.apple.com/en-us/HT201222

Trust: 0.8

title:APPLE-SA-2016-12-12-3 tvOS 10.1url:https://lists.apple.com/archives/security-announce/2016/Dec/msg00002.html

Trust: 0.8

title:APPLE-SA-2016-12-13-1 macOS 10.12.2url:https://lists.apple.com/archives/security-announce/2016/Dec/msg00003.html

Trust: 0.8

title:APPLE-SA-2017-01-23-3 watchOS 3.1.3url:https://lists.apple.com/archives/security-announce/2017/Jan/msg00004.html

Trust: 0.8

title:APPLE-SA-2016-12-12-1 iOS 10.2url:https://lists.apple.com/archives/security-announce/2016/Dec/msg00000.html

Trust: 0.8

title:HT207487url:https://support.apple.com/en-us/HT207487

Trust: 0.8

title:HT207425url:https://support.apple.com/en-us/HT207425

Trust: 0.8

title:HT207422url:https://support.apple.com/en-us/HT207422

Trust: 0.8

title:HT207423url:https://support.apple.com/en-us/HT207423

Trust: 0.8

title:HT207425url:https://support.apple.com/ja-jp/HT207425

Trust: 0.8

title:HT207423url:https://support.apple.com/ja-jp/HT207423

Trust: 0.8

title:HT207487url:https://support.apple.com/ja-jp/HT207487

Trust: 0.8

title:HT207422url:https://support.apple.com/ja-jp/HT 207422

Trust: 0.8

title:Multiple Apple product Kernel Fixes for component security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=66491

Trust: 0.6

sources: JVNDB: JVNDB-2016-007438 // CNNVD: CNNVD-201612-457

EXTERNAL IDS

db:NVDid:CVE-2016-7621

Trust: 3.1

db:BIDid:94905

Trust: 2.0

db:EXPLOIT-DBid:40956

Trust: 1.1

db:SECTRACKid:1037469

Trust: 1.1

db:JVNid:JVNVU97133642

Trust: 0.8

db:JVNid:JVNVU97915630

Trust: 0.8

db:JVNid:JVNVU93979172

Trust: 0.8

db:JVNDBid:JVNDB-2016-007438

Trust: 0.8

db:CNNVDid:CNNVD-201612-457

Trust: 0.7

db:PACKETSTORMid:140246

Trust: 0.1

db:VULHUBid:VHN-96441

Trust: 0.1

db:PACKETSTORMid:140688

Trust: 0.1

db:PACKETSTORMid:140156

Trust: 0.1

db:PACKETSTORMid:140157

Trust: 0.1

sources: VULHUB: VHN-96441 // BID: 94905 // JVNDB: JVNDB-2016-007438 // PACKETSTORM: 140688 // PACKETSTORM: 140156 // PACKETSTORM: 140157 // CNNVD: CNNVD-201612-457 // NVD: CVE-2016-7621

REFERENCES

url:http://www.securityfocus.com/bid/94905

Trust: 1.7

url:https://support.apple.com/ht207422

Trust: 1.7

url:https://support.apple.com/ht207423

Trust: 1.7

url:https://support.apple.com/ht207487

Trust: 1.7

url:https://www.exploit-db.com/exploits/40956/

Trust: 1.1

url:http://www.securitytracker.com/id/1037469

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-7621

Trust: 0.8

url:http://jvn.jp/vu/jvnvu97133642/index.html

Trust: 0.8

url:http://jvn.jp/vu/jvnvu97915630/index.html

Trust: 0.8

url:http://jvn.jp/vu/jvnvu93979172/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-7621

Trust: 0.8

url:https://support.apple.com/en-in/ht207425

Trust: 0.6

url:http://www.apple.com/ios/

Trust: 0.3

url:http://www.apple.com/accessibility/tvos/

Trust: 0.3

url:http://www.apple.com/watchos-2/

Trust: 0.3

url:http://www.apple.com/ipad/

Trust: 0.3

url:http://www.apple.com/iphone/

Trust: 0.3

url:http://www.apple.com/ipodtouch/

Trust: 0.3

url:http://www.apple.com/macosx/

Trust: 0.3

url:https://lists.apple.com/archives/security-announce/2017/jan/msg00004.html

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7627

Trust: 0.3

url:https://support.apple.com/kb/ht201222

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7615

Trust: 0.3

url:https://gpgtools.org

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7616

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7588

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7607

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7621

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-4691

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7591

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-4693

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7606

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-4688

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7612

Trust: 0.3

url:https://www.apple.com/support/security/pgp/

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7619

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7589

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7594

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7595

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7626

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7636

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-7643

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7657

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7660

Trust: 0.2

url:https://support.apple.com/kb/ht204641

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7662

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7637

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7644

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7663

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7659

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7658

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7651

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7599

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7635

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7632

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7586

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7610

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7587

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-4692

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7611

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-4743

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-7598

Trust: 0.1

sources: VULHUB: VHN-96441 // BID: 94905 // JVNDB: JVNDB-2016-007438 // PACKETSTORM: 140688 // PACKETSTORM: 140156 // PACKETSTORM: 140157 // CNNVD: CNNVD-201612-457 // NVD: CVE-2016-7621

CREDITS

Haohao Kong of Keen Lab of Tencent, an anonymous researcher, riusksk of Tencent Security Platform Department, Dragonltx of Huawei 2012 Laboratories, TRAPMINE Inc. & Meysam Firouzi @R00tkitSMM, daybreaker@Minionz working with Trend Micro's Zero Day Initiat

Trust: 0.6

sources: CNNVD: CNNVD-201612-457

SOURCES

db:VULHUBid:VHN-96441
db:BIDid:94905
db:JVNDBid:JVNDB-2016-007438
db:PACKETSTORMid:140688
db:PACKETSTORMid:140156
db:PACKETSTORMid:140157
db:CNNVDid:CNNVD-201612-457
db:NVDid:CVE-2016-7621

LAST UPDATE DATE

2024-11-23T21:25:35.036000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-96441date:2018-10-30T00:00:00
db:BIDid:94905date:2017-02-02T00:02:00
db:JVNDBid:JVNDB-2016-007438date:2017-03-01T00:00:00
db:CNNVDid:CNNVD-201612-457date:2017-03-01T00:00:00
db:NVDid:CVE-2016-7621date:2024-11-21T02:58:19.133

SOURCES RELEASE DATE

db:VULHUBid:VHN-96441date:2017-02-20T00:00:00
db:BIDid:94905date:2016-12-13T00:00:00
db:JVNDBid:JVNDB-2016-007438date:2017-03-01T00:00:00
db:PACKETSTORMid:140688date:2017-01-24T00:59:01
db:PACKETSTORMid:140156date:2016-12-14T15:55:53
db:PACKETSTORMid:140157date:2016-12-14T16:32:22
db:CNNVDid:CNNVD-201612-457date:2016-12-15T00:00:00
db:NVDid:CVE-2016-7621date:2017-02-20T08:59:02.823