CVE-2023-27951: Use After Free
Published Mar 27, 2023
·Updated
AMD. A buffer overflow issue was addressed with improved memory handling.
Credit
Brandon Dalton@@partyD0lphin(Red Canary), Csaba Fitzl@@theevilbit(Offensive Security), Chan Shue Long(Offensive Security), (Offensive Security), Mickey Jin@@patch1t, Rıza Sabuncu@@rizasabuncu, JeongOhKyea, Tingting Yin(Tsinghua University), Aleksandar Nikolic(Cisco Talos), an anonymous researcher, Ye Zhang@@VAR10CK(Baidu Security), ryuzaki, Murray Mike, Arsenii Kostromin (0x3c3e), Félix Poulin-Bélanger, David Pan Ogea, Xinru Chi(Pangu Lab), Ned Williamson(Google Project Zero), Pan ZhenPeng(STAR Labs SG Pte), Zweig(Kunlun Lab), Joshua Jones, Zhuowei Zhang, Adam M., Guilherme Rambo(Best Buddy Apps), CVE-2023-0433, CVE-2023-0512, Wojciech Reguła@@_r3ggi(SecuRing), sqrtpwn, Mickey Jin@@patch1t(FFRI Security Inc), Koh M. Nakagawa(FFRI Security Inc), Yiğit Can YILMAZ@@yilmazcanyigit, Jubaer Alnazi Jabin(TRS Group Of Companies), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Mohamed GHANNAM@@_simo36, Antonio Zekic@@antoniozekic, John Aakerblom@@jaakerblom, ABC Research s.r.o., Mohamed Ghannam@@_simo36, Junoh Lee at Theori, CVE-2022-43551, CVE-2022-43552, Mikko Kenttälä )@@Turmio_(SensorFu), Jubaer Alnazi(TRS Group of Companies), jzhu(Trend Micro Zero Day Initiative), Meysam Firouzi@@R00tkitSMM(Mbition Mercedes), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Adam Doupé(ASU SEFCOM), an anonymous researcher(Red Canary), Milan Tenk(F), (F), Arthur Valiev(F), developStorm, Khiem Tran, Masahiro Kawada@@kawakatz(GMO Cybersecurity by Ierae), (Alibaba Group), Xin Huang@@11iaxH, CVE-2023-0049, CVE-2023-0051, CVE-2023-0054, CVE-2023-0288, Gertjan Franken(imec), KU Leuven, hazbinhotel(Trend Micro Zero Day Initiative), Georgy Kucherin@@kucher1n(Kaspersky), Leonid Bezvershenko@@bzvr_(Kaspersky), Boris Larin@@oct0xor(Kaspersky), (Kaspersky), Valentin Pashkov(Kaspersky), Anonymous(Trend Micro Zero Day Initiative), Dohyun Lee@@l33d0hyun(SSD Labs), crixer@@pwning_me(SSD Labs)
Affected Software
6 affected componentsFixes available
Apple macOS Big Sur<11.7.5
11.7.5
macOS<12.6.4
12.6.4
macOS Ventura<13.3
13.3
macOS<11.7.5
macOS>=12.0<12.6.4
macOS>=13.0<13.3
Event History
Mar 27, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
May 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
08:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-27951.
2
What is the severity level of CVE-2023-27951?
The severity level of CVE-2023-27951 is medium.
3
How can the vulnerability be exploited?
The vulnerability can be exploited through an archive that may be able to bypass Gatekeeper.
4
Which software versions are affected by CVE-2023-27951?
CVE-2023-27951 affects macOS Ventura up to version 13.3, macOS Monterey up to version 12.6.4, and macOS Big Sur up to version 11.7.5.
5
How was CVE-2023-27951 addressed?
CVE-2023-27951 was addressed with improved checks in macOS Ventura 13.3, macOS Monterey 12.6.4, and macOS Big Sur 11.7.5.