CVE-2021-30860
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 13, 2021
- Published Date
- August 24, 2021
- Last Updated
- February 03, 2025
- Vendor
- Apple
- Product
- macOS, watchOS, iOS
- Description
- An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVSS Scores
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
https://support.apple.com/en-us/HT212804
https://support.apple.com/en-us/HT212805
https://support.apple.com/en-us/HT212807
https://support.apple.com/en-us/HT212806
http://seclists.org/fulldisclosure/2021/Sep/28
http://seclists.org/fulldisclosure/2021/Sep/27
http://seclists.org/fulldisclosure/2021/Sep/25
http://seclists.org/fulldisclosure/2021/Sep/26
http://seclists.org/fulldisclosure/2021/Sep/40
http://seclists.org/fulldisclosure/2021/Sep/38
http://seclists.org/fulldisclosure/2021/Sep/39
https://support.apple.com/kb/HT212824
http://seclists.org/fulldisclosure/2021/Sep/50
http://www.openwall.com/lists/oss-security/2022/09/02/11
https://security.gentoo.org/glsa/202209-21
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
jeffssh/CVE-2021-30860
Type: github • Created: 2021-12-25 03:00:01 UTC • Stars: 96
Collection of materials relating to FORCEDENTRY
Levilutz/CVE-2021-30860
Type: github • Created: 2021-09-18 22:14:17 UTC • Stars: 11
Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit