Rewterz Threat Alert – Donot APT Group – Active IOCs
May 18, 2023Rewterz Threat Advisory – CVE-2023-32336 – IBM InfoSphere Information Server Vulnerability
May 22, 2023Rewterz Threat Alert – Donot APT Group – Active IOCs
May 18, 2023Rewterz Threat Advisory – CVE-2023-32336 – IBM InfoSphere Information Server Vulnerability
May 22, 2023Severity
Medium
Analysis Summary
CVE-2023-32360 CVSS:6.2
Apple macOS Big Sur could allow a local attacker to obtain sensitive information, caused by an authentication issue in the CUPS component. An attacker could exploit this vulnerability to obtain recently printed documents and use this information to launch further attacks against the affected system.
CVE-2023-32387 CVSS:8.4
Apple macOS Big Sur could allow a local attacker to execute arbitrary code on the system, caused by a use-after-free in the dcerpc component. An attacker could exploit this vulnerability to execute arbitrary code on the system or cause unexpected app termination.
CVE-2023-32369 CVSS:6.2
Apple macOS Big Sur could allow a remote attacker to bypass security restrictions, caused by a logic issue in the libxpc component. By executing a specially crafted application, an attacker could exploit this vulnerability to modify protected parts of the file system.
CVE-2023-32405 CVSS:8.4
Apple macOS Big Sur could allow a local attacker to gain elevated privileges on the system, caused by a logic issue in the libxpc component. By executing a specially crafted application, an attacker could exploit this vulnerability to gain root privileges on the system.
CVE-2023-32380 CVSS:8.4
Apple macOS Big Sur could allow a local attacker to execute arbitrary code on the system, caused by an n out-of-bounds write in the Model I/O component when processing 3D models. An attacker could exploit this vulnerability to execute arbitrary code on the system.
CVE-2023-32382 CVSS:6.2
Apple macOS Big Sur could allow a local attacker to obtain sensitive information, caused by an out-of-bounds read in the Model I/O component when processing3d models. An attacker could exploit this vulnerability to obtain sensitive information from process information and use this information to launch further attacks against the affected system.
CVE-2023-32355 CVSS:6.2
Apple macOS Big Sur could allow a local attacker to bypass security restrictions, caused by a logic issue in the PackageKit component. By executing a specially crafted application, an attacker could exploit this vulnerability to modify protected parts of the file system.
CVE-2023-32395 CVSS:6.2
Apple macOS Big Sur could allow a local attacker to bypass security restrictions, caused by a logic issue in the Perl component. By executing a specially crafted application, an attacker could exploit this vulnerability to modify protected parts of the file system.
CVE-2023-32386 CVSS:6.2
Apple macOS Big Sur could allow a local attacker to obtain sensitive information, caused by a privacy issue in the Contacts component. By executing a specially crafted application, an attacker could exploit this vulnerability to observe unprotected user data.
Impact
- Code Execution
- Privilege Escalation
- Security Bypass
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2023-32360
- CVE-2023-32387
- CVE-2023-32369
- CVE-2023-32405
- CVE-2023-32380
- CVE-2023-32382
- CVE-2023-32355
- CVE-2023-32395
- CVE-2023-32386
Affected Vendors
Apple
Affected Products
- Apple macOS Big Sur 11.7.7
Remediation
Refer to Apple Security Advisory for patch, upgrade or suggested workaround information.