CVE-2021-1857
Last modified
CVE-2021-1857 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Icloud | < 12.3 |
| Apple | Itunes | < 12.11.3 |
| Apple | Ipados | < 14.5 |
| Apple | Iphone Os | < 14.5 |
| Apple | Mac Os X | 10.14 |
| Apple | Mac Os X | 10.14.0 |
| Apple | Mac Os X | 10.14.1 |
| Apple | Mac Os X | 10.14.2 |
| Apple | Mac Os X | 10.14.3 |
| Apple | Mac Os X | 10.14.4 |
| Apple | Mac Os X | 10.14.5 |
| Apple | Mac Os X | 10.14.6 |
| Apple | Mac Os X | 10.15 |
| Apple | Mac Os X | 10.15.1 |
| Apple | Mac Os X | 10.15.2 |
| Apple | Mac Os X | 10.15.3 |
| Apple | Mac Os X | 10.15.4 |
| Apple | Mac Os X | 10.15.5 |
| Apple | Mac Os X | 10.15.6 |
| Apple | Mac Os X | 10.15.7 |
| Apple | Macos | >= 11.0, < 11.3 |
| Apple | Tvos | < 14.5 |
| Apple | Watchos | < 7.4 |
References
- https://support.apple.com/en-us/HT212317Vendor Advisory
- https://support.apple.com/en-us/HT212319Vendor Advisory
- https://support.apple.com/en-us/HT212321Vendor Advisory
- https://support.apple.com/en-us/HT212323Vendor Advisory
- https://support.apple.com/en-us/HT212324Vendor Advisory
- https://support.apple.com/en-us/HT212325Vendor Advisory
- https://support.apple.com/en-us/HT212326Vendor Advisory
- https://support.apple.com/en-us/HT212327Vendor Advisory
- https://support.apple.com/en-us/HT212317Vendor Advisory
- https://support.apple.com/en-us/HT212319Vendor Advisory
- https://support.apple.com/en-us/HT212321Vendor Advisory
- https://support.apple.com/en-us/HT212323Vendor Advisory
- https://support.apple.com/en-us/HT212324Vendor Advisory
- https://support.apple.com/en-us/HT212325Vendor Advisory
- https://support.apple.com/en-us/HT212326Vendor Advisory
- https://support.apple.com/en-us/HT212327Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-1857?
How severe is CVE-2021-1857?
How do I fix CVE-2021-1857?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-1849An issue in code signature validation was addressed with imp…7.5
- CVE-2021-1851A logic issue was addressed with improved state management. …8.8
- CVE-2021-1852An out-of-bounds read was addressed with improved input vali…5.5
- CVE-2021-1853A logic issue was addressed with improved state management. …7.8
- CVE-2021-1854A call termination issue with was addressed with improved lo…4.3
- CVE-2021-1855A logic issue was addressed with improved state management. …6.5
- CVE-2021-1858Processing a maliciously crafted image may lead to arbitrary…7.8
- CVE-2021-1859A logic issue was addressed with improved state management. …7.5
- CVE-2021-1860A memory initialization issue was addressed with improved me…6.5
- CVE-2021-1861An issue existed in determining cache occupancy. The issue w…4.3
- CVE-2021-1862Description: A person with physical access may be able to ac…2.4
- CVE-2021-1863An issue existed with authenticating the action triggered by…2.4
Are you affected by CVE-2021-1857?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
