Skip to content
COOEY

EXPOSURES › CVE-2023-32434

CVE-2023-32434

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-32434 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

An integer overflow vulnerability in Apple's operating systems allows applications to potentially execute code with kernel privileges, and is currently being exploited in the wild.

CVE-2023-32434 represents an integer overflow vulnerability affecting iOS, iPadOS, macOS, and watchOS, enabling potential code execution with kernel privileges. DIB organizations using these platforms must immediately apply Apple's security updates to mitigate the risk of unauthorized access and control. Failure to patch exposes systems to potential compromise and non-compliance with NIST 800-171 requirements.

Shame score — The vulnerability's active exploitation and potential for kernel-level code execution demonstrate a significant security oversight by Apple, impacting a wide range of devices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.