EXPOSURES › CVE-2014-4404
CVE-2014-4404
HIGH ⌖ ON CISA KEV · EXPLOITEDApple OS X suffered a heap-based buffer overflow in IOHIDFamily allowing privileged code execution.
A heap-based buffer overflow in Apple OS X's IOHIDFamily component allowed attackers to execute arbitrary code with elevated privileges. DIB organizations must ensure all Apple OS X devices are patched, as this vulnerability was actively exploited in the wild and represents a significant compliance risk under NIST 800-171 for unpatched systems.
Shame score — The vulnerability was actively exploited in the wild and allowed arbitrary code execution in a privileged context, indicating a severe and avoidable failure in Apple's security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.