NVD disclosure day

Published threat advisories for December 8, 2020

CVE advisoryKnown Exploit

CVE-2020-27950

Apple Operating System Kernel Memory Disclosure Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory initialization issue in Apple operating systems could allow a malicious application to disclose kernel memory. This may impact the confidentiality of system data. The risk to organizations is considered low, as exploitation requires a malicious application already running on the device.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-27932

Apple Operating System Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A type confusion flaw in Apple operating systems may allow a malicious application to execute arbitrary code with kernel privileges. This could lead to unauthorized control of affected devices, posing a risk to data integrity and system availability. Organizations should apply vendor updates to mitigate this vulnerabil

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-27930

Apple Font Processing Vulnerability Leading to Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability exists in Apple operating systems, potentially allowing arbitrary code execution if a user opens a maliciously crafted font file. This poses a risk of unauthorized system control and data compromise. Organizations should apply vendor updates to mitigate this threat.

• CISA KEV