CVE-2020-3861: High severity apple Itunes Windows vulnerability
Mobile Device Service. The issue was addressed with improved permissions logic.
Other sources
The issue was addressed with improved permissions logic. This issue is fixed in iTunes for Windows 12.10.4. A user may gain access to protected parts of the file system.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
iTunesto a version that resolves this vulnerability.Fixed in 12.10.4 - Upgrade
Upgrade
iTunes for Windows (Mobile Device Service)to a version that resolves this vulnerability.Fixed in 12.10.4
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-3861.
What is the affected software?
The affected software is iTunes for Windows version up to exclusive 12.10.4.
What was the issue addressed in this vulnerability?
The issue addressed in this vulnerability is related to improved permissions logic in the Mobile Device Service.
How can I fix this vulnerability?
To fix this vulnerability, update iTunes for Windows to version 12.10.4 or higher.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found on the Apple support website at https://support.apple.com/en-us/HT210923.