Vulnerability Description
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves CFPreferences in the "System Preferences" component. It allows attackers to bypass intended access restrictions by leveraging incorrect configuration-profile persistence.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | < 11.3 |
| Apple | Mac Os X | < 10.13.4 |
| Apple | Tvos | < 11.3 |
| Apple | Watchos | < 4.3 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1040604Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040608Third Party AdvisoryVDB Entry
- https://support.apple.com/HT208692Vendor Advisory
- https://support.apple.com/HT208693Vendor Advisory
- https://support.apple.com/HT208696Vendor Advisory
- https://support.apple.com/HT208698Vendor Advisory
- http://www.securitytracker.com/id/1040604Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040608Third Party AdvisoryVDB Entry
- https://support.apple.com/HT208692Vendor Advisory
- https://support.apple.com/HT208693Vendor Advisory
- https://support.apple.com/HT208696Vendor Advisory
- https://support.apple.com/HT208698Vendor Advisory
FAQ
What is CVE-2018-4115?
CVE-2018-4115 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves CFPre...
How severe is CVE-2018-4115?
CVE-2018-4115 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-4115?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Iphone Os, Apple Mac Os X, Apple Tvos, Apple Watchos.