Skip to content
COOEY

EXPOSURES › CVE-2021-30983

CVE-2021-30983

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-27 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-30983 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

A buffer overflow in iOS and iPadOS allowed code execution with kernel privileges, actively exploited in the wild and impacting DIB organizations using Apple devices in their environments.

CVE-2021-30983 represents a buffer overflow vulnerability in Apple's iOS and iPadOS, enabling arbitrary code execution at the kernel level. This is particularly concerning for DIB organizations as it could lead to system compromise and data exfiltration, directly impacting CMMC compliance. Immediate patching and vulnerability scanning are critical.

Shame score — The vulnerability's exploitation in the wild and potential for kernel-level code execution demonstrates a significant security oversight by Apple, warranting a high embarrassment score.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.