CVE-2017-7110
CRITICAL severity · CVSS 9.8 · Memory corruption
9.8CVSS CRITICAL
Summary
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)4%
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- https://support.apple.com/HT208112Advisory
- https://support.apple.com/HT208113Advisory
- https://support.apple.com/HT208115Advisory
- http://www.securityfocus.com/bid/100927Advisory
- http://www.securitytracker.com/id/1039385Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1313Advisory