NVD disclosure day

Published threat advisories for December 18, 2019

CVE advisoryKnown Exploit

CVE-2019-8605

Apple OS Vulnerability Allows Code Execution By Malicious Apps

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory management flaw in Apple operating systems could permit a malicious application to execute code with system privileges. This impacts the integrity and confidentiality of data, posing a business risk of system compromise and potential data breaches. Organizations should apply vendor updates to mitigate this ris

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-8526

macOS Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free flaw in macOS may allow an application to gain elevated privileges. This could impact system integrity and lead to unauthorized access. The risk is associated with local exploitation. The issue is addressed in macOS Mojave 10.14.4.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-8506

Apple Products Code Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A type confusion vulnerability in certain Apple products allows for arbitrary code execution by processing maliciously crafted web content. This poses a risk to affected organizations, employees, and systems by potentially enabling attackers to gain control and compromise data. The business risk stems from unauthorized

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-7287

iPhone OS Memory Corruption Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability in iOS may allow a malicious application to execute arbitrary code with kernel privileges. This presents a business risk by potentially compromising data confidentiality and integrity on affected devices. Organizations should apply vendor updates to mitigate this risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-7286

Apple Product Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption flaw in Apple operating systems could allow an application to gain elevated privileges. This impacts system integrity and data confidentiality. The realistic business risk involves unauthorized access and control over affected systems.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-4716

IBM Planning Analytics: Unauthorized Access and Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

IBM Planning Analytics can be exploited by unauthenticated users to gain administrative access and execute code as root or SYSTEM. This exposes affected organizations to business risk from unauthorized system control and potential data compromise.

• CISA KEV